CVE-2025-66249

CVE-2025-66249: Apache Livy: Unauthorized directory access

Vendor Apache Software Foundation
Product Apache Livy
Weakness CWE-22 · Path traversal
Published March 13, 2026
Last update March 13, 2026

CVSS base score

What the vulnerability does

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration value "livy.file.local-dir-whitelist" is set to a non-default value, the directory checking can be bypassed. Users are recommended to upgrade to version 0.9.0, which fixes the issue.

Key dates

Disclosure timeline

March 13, 2026 CVE published
March 13, 2026 Record updated