Skip to content
linkisGHSA-c399-q49h-qwc8

Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass

High7.5CVE-2025-29847 · Published Jan 19, 2026 · updated Feb 3, 2026

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the system's checks. This bypass can trigger a vulnerability that allows unauthorized access to system files via JDBC parameters. Scope of Impact This issue affects Apache Linkis: from 1.3.0 through 1.7.0. Severity level moderate Solution Continuously check if the connection information contains the "%" character; if it does, perform URL decoding. Users are recommended to upgrade to version 1.8.0, which fixes the issue. More questions about this vulnerability can be discussed here:  https://lists.apache.org/list?dev@linkis.apache.org:2025-9:cve

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.linkis:linkis
Maven
>= 1.3.0, < 1.8.01.8.0
Details and references

More linkis advisories

All linkis
Advisory
Apache Linkis arbitrary file deletion vulnerability
High4.9Aug 2, 2024
Apache Linkis vulnerable to privilege escalation
High5.3Aug 2, 2024
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Medium5.3Mar 6, 2024
Apache Linkis Authentication Bypass vulnerability
Critical9.1Jul 6, 2023
Apache Linkis Zip Slip issue
Critical9.8Jul 6, 2023
Apache Linkis Unrestricted File Upload vulnerability
Critical9.8Jul 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.