← back
CVE-2025-46822highCWE-36

Unauthenticated Arbitrary File Read via Absolute Path

56Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.7epss 4.0%
from disclosure to weapon2 days
Published on NVDMay 21
1st PoC+2d
exploitation probability
4.0%top 10% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.