ZeroHour

CVE-2025-56769

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p27
Published
()
Modified
Description

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.

Vendors
hutool
Products
hutool
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.