CVE-2026-6125: Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6125?
CVE-2026-6125 is classified as a code injection vulnerability that can lead to critical security issues.
How do I fix CVE-2026-6125?
To fix CVE-2026-6125, upgrade to Dromara warm-flow version 1.8.5 or later.
What component is affected by CVE-2026-6125?
CVE-2026-6125 affects the SpelHelper.parseExpression function in the Workflow Definition Handler.
What is the impact of CVE-2026-6125?
The impact of CVE-2026-6125 includes potential unauthorized code execution due to code injection.
Which versions of Dromara warm-flow are affected by CVE-2026-6125?
CVE-2026-6125 affects Dromara warm-flow versions up to and including 1.8.4.