CVE-2025-56769

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
References
Link Resource
https://github.com/chinabugotech/hutool/issues/3994 Exploit Patch Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-25 23:15

Updated : 2025-10-03 18:37


NVD link : CVE-2025-56769

Mitre link : CVE-2025-56769

CVE.ORG link : CVE-2025-56769


JSON object : View

Products Affected

hutool

  • hutool
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')