CVE-2025-56769: Command Injection
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
Other sources
An issue was discovered in chinabugotech hutool before 5.8.40 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56769?
CVE-2025-56769 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2025-56769?
To fix CVE-2025-56769, upgrade to Hutool version 5.8.4 or later.
What types of attacks can CVE-2025-56769 facilitate?
CVE-2025-56769 can facilitate arbitrary method invocation and remote code execution attacks.
Which versions of Hutool are affected by CVE-2025-56769?
Hutool versions before 5.8.4 are affected by CVE-2025-56769.
Is CVE-2025-56769 specific to any particular class in Hutool?
Yes, CVE-2025-56769 specifically affects the QLExpressEngine class in Hutool.