CVE-2025-66249

CVE-2025-66249: Apache Livy: Unauthorized directory access

Vendor Apache Software Foundation
Product Apache Livy
Weakness CWE-22 · Path traversal
Published March 13, 2026
Last update March 13, 2026

CVSS base score

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration value "livy.file.local-dir-whitelist" is set to a non-default value, the directory checking can be bypassed. Users are recommended to upgrade to version 0.9.0, which fixes the issue.

Key dates

02Disclosure timeline

March 13, 2026 CVE published
March 13, 2026 Record updated

Related vulnerabilities

04Related CVE