References https://nvd.nist.gov/vuln/detail/CVE-2025-49493 https://github.com/SystemVll/CVE-2025-49493 https://xbow.com/blog/xbow-akamai-cloudtest-xxe https://www.tenable.com/cve/CVE-2025-49493 https://techdocs.akamai.com/cloudtest/changelog/june-2-2025-enhancements-and-bug-fixes/ https://github.com/advisories/GHSA-g536-463c-q7r3 https://sploitus.com/exploit?id=006DE3B1-1DD0-5F5A-A5EB-3317056C5CC3 https://www.cve.org/CVERecord?id=CVE-2025-49493
Related VulnerabilitiesPoCCVE-2025-49493: Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)PoCakamai-content-csp-bypass: Content-Security-Policy Bypass - Akamai ContentPoCakamai-arl-xss: Open Akamai ARL - Cross-Site ScriptingPoCakamai-s3-cache-poisoning: Akamai/Amazon S3 - Cache PoisoningAkamai CloudTest /concerto/services/RepositoryService XML外部实体注入漏洞(CVE-2025-49493)(CVE-2025-49493) Akamai CloudTest before 60 2025.06.02 XXE注入导致文件包含漏洞