CVE-2025-66905
EUVD-2025-20454519.12.2025, 16:15
The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| takes | tkfiles | 2.0 |
𝑥
= Vulnerable software versions