PT-2025-52458 · Takes · Takes

Xzzz111

·

Published

2025-12-19

·

Updated

2026-01-06

·

CVE-2025-66905

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Takes versions through 2.0-SNAPSHOT
Description The Takes web framework’s TkFiles component does not properly sanitize HTTP request paths before using them to access the filesystem. This allows a remote attacker to use "../" sequences within the request path to bypass the intended base directory and potentially read arbitrary files from the system. The TkFiles take is the affected component.
Recommendations Update to a version beyond 2.0-SNAPSHOT.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66905

Affected Products

Takes