Remote Code Execution Vulnerability in Ladybug Java Debugging Tool
CVE-2025-66214
What is CVE-2025-66214?
Ladybug, a tool that enhances Java applications with message-based debugging and testing capabilities, contains a significant vulnerability in versions prior to 3.0-20251107.114628. The impacted APIs, /iaf/ladybug/api/report/{storage} and /iaf/ladybug/api/report/upload, permit the upload of gzip-compressed XML files that can contain malicious content. This vulnerability allows attackers to exploit the system by submitting specially crafted XML payloads, leading to Remote Code Execution and unauthorized access to the server. This issue has been addressed in the latest version of Ladybug.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ladybug < 3.0-20251107.114628
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
