PT-2025-50222 · Ladybug · Ladybug

R1Ckyz

·

Published

2025-12-09

·

Updated

2025-12-17

·

CVE-2025-66214

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ladybug versions prior to 3.0-20251107.114628
Description Ladybug is a tool that adds message-based debugging, unit, system, and regression testing to Java applications. The software contains the API endpoints /iaf/ladybug/api/report/{storage} and /iaf/ladybug/api/report/upload, which permit the upload of gzip-compressed XML files with user-controllable content. The system deserializes these XML files, potentially allowing an attacker to achieve Remote Code Execution (RCE) by submitting specially crafted XML payloads and gaining access to the target server. The vulnerable parameters are the content of the uploaded XML files.
Recommendations Update to version 3.0-20251107.114628.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-66214
GHSA-F9FH-R3CV-398F

Affected Products

Ladybug