Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcqr-rc2q-63p5

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.4

Описание

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

EPSS

Процентиль: 17%
0.00055
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.4
nvd
около 1 месяца назад

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

EPSS

Процентиль: 17%
0.00055
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-94