Remote Code Execution Vulnerability in Ladybug Java Debugging Tool
CVE-2025-66214

7HIGH

Key Information:

Vendor

Wearefrank

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-66214?

Ladybug, a tool that enhances Java applications with message-based debugging and testing capabilities, contains a significant vulnerability in versions prior to 3.0-20251107.114628. The impacted APIs, /iaf/ladybug/api/report/{storage} and /iaf/ladybug/api/report/upload, permit the upload of gzip-compressed XML files that can contain malicious content. This vulnerability allows attackers to exploit the system by submitting specially crafted XML payloads, leading to Remote Code Execution and unauthorized access to the server. This issue has been addressed in the latest version of Ladybug.

Affected Version(s)

ladybug < 3.0-20251107.114628

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.