/Vulnerability Library

Spring Framework - Path Traversal

CVE-2025-41242
Verified

Description

Spring Framework MVC applications deployed as WAR or with embedded Servlet containers that do not reject suspicious URI sequences and serve static resources with Spring resource handling contain a path traversal vulnerability, letting attackers access unauthorized files, exploit requires non-compliant Servlet container configuration.

Severity

Medium

CVSS Score

5.9

Exploit Probability

2%

Published Date

May 4, 2026

Template Author

dhiyaneshdk

CVE-2025-41242.yaml
5.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-41242
CWE ID:
cwe-22

References

https://x.com/phithon_xg/status/2048853566564221372https://github.com/vulhub/vulhub/tree/master/spring/CVE-2025-41242https://i.blackhat.com/Asia-26/Presentations/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdfhttps://nvd.nist.gov/vuln/detail/CVE-2025-41242

Remediation Steps

Upgrade to the latest Spring Framework version and ensure deployment on compliant Servlet containers with default security features enabled.