CVE-2025-43766
Java vulnerability analysis and mitigation

Overview

CVE-2025-43766 is an unrestricted file upload vulnerability (CWE-434) in the style books component of Liferay Portal and Liferay DXP that enables arbitrary code execution by attackers. It affects Liferay Portal versions 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92. The vulnerability was published on August 23, 2025, with a patch available for the affected Maven package com.liferay:com.liferay.style.book.web prior to version 2.0.117. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Liferay Advisory).

Technical details

The root cause is CWE-434 (Unrestricted Upload of File with Dangerous Type): the style books component in Liferay Portal and DXP fails to properly validate or restrict the types of files that can be uploaded, and those uploaded files are subsequently processed within the server environment. This allows an attacker to upload a malicious file (e.g., a server-side script or executable) that is then executed by the application server, resulting in arbitrary code execution. The vulnerable Maven artifact is com.liferay:com.liferay.style.book.web in versions prior to 2.0.117, and the fix is tracked under Liferay issue LPE-18145 (GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code on the affected Liferay Portal or DXP server, resulting in full compromise of confidentiality, integrity, and availability of the system. An attacker could gain unauthorized access to sensitive data stored within the platform, modify or destroy content, establish persistent backdoors, and potentially pivot to other systems within the network. The CVSS v3.1 score of 9.8 reflects the high impact across all three security dimensions with no authentication required (GitHub Advisory, Liferay Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Liferay Portal or DXP instances using tools like Shodan or Censys, targeting versions within the affected ranges (Portal 7.4.0–7.4.3.131, DXP 7.4 GA–update 92, or DXP 2024.Q1–Q4 affected releases).
  2. Authentication: Obtain or create an account with sufficient privileges to access the Style Books component in Liferay's design/theming administration area (the CVSS v4 metric indicates high privileges are required for the base scenario, though the v3.1 score of 9.8 suggests no privileges may be required in some configurations).
  3. Navigate to Style Books: Access the Style Books management interface, typically found under the site administration panel in Liferay Portal/DXP.
  4. Upload malicious file: Upload a file with a dangerous type (e.g., a JSP web shell or server-side script) through the Style Books file upload functionality, bypassing any client-side or insufficient server-side validation.
  5. Trigger execution: Access or reference the uploaded file via its server path to cause the application server to process and execute the malicious payload, achieving remote code execution.
  6. Post-exploitation: Use the established shell to exfiltrate data, establish persistence, or move laterally within the network (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST requests to Liferay Style Books upload endpoints (e.g., paths containing /style-books/ or /o/style-book-web/) with non-standard file types (e.g., .jsp, .jspx, .war, .sh); unexpected outbound connections from the Liferay server to external IPs.
  • File System: Presence of unexpected script files (.jsp, .jspx, .py, .sh) in Liferay's document library, style books directory, or web application deployment directories; newly created files in [LIFERAY_HOME]/webapps/ or temp directories.
  • Logs: Liferay access logs showing file upload requests to style books endpoints with unusual MIME types or file extensions; application server logs (e.g., Tomcat catalina.out) showing execution of unexpected scripts or Java errors related to file processing.
  • Process: Unexpected child processes spawned by the Liferay/Tomcat JVM process (e.g., bash, sh, curl, wget, python); unusual network connections initiated by the Java process.

Mitigation and workarounds

Liferay has released a patch in the Maven package com.liferay:com.liferay.style.book.web version 2.0.117 and later. For Liferay Portal, upgrade to version 7.4.3.132 or later; for Liferay DXP, apply the relevant quarterly update beyond the affected ranges (2024.Q1.14+, 2024.Q2.14+, 2024.Q3.14+, or a later quarterly release). As interim workarounds, restrict access to the Style Books administration interface to trusted administrators only, implement a Web Application Firewall (WAF) to block uploads of dangerous file types, and monitor file upload activity for anomalies (GitHub Advisory, Liferay Advisory).

Community reactions

The vulnerability was noted by automated CVE tracking accounts on X (formerly Twitter) shortly after publication on August 23, 2025 (X/CVEnew). Red Hat published a security advisory entry for the CVE on August 25, 2025 (Red Hat). No significant independent researcher commentary or broader media coverage has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56741HIGH7.5
  • Java logoJava
  • jline
NoYesJul 17, 2026
CVE-2026-56740HIGH7.5
  • Java logoJava
  • jline2
NoYesJul 17, 2026
CVE-2026-49485HIGH7.5
  • Java logoJava
  • ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
NoYesJul 17, 2026
CVE-2026-44891HIGH7.5
  • Java logoJava
  • apache-hop-fips
NoYesJul 17, 2026
CVE-2026-45799HIGH7.5
  • Java logoJava
  • com.squareup.wire:wire-runtime
NoYesJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management