CVE-2025-56769

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
References
Link Resource
https://github.com/chinabugotech/hutool/issues/3994 Exploit Patch Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*

History

03 Oct 2025, 18:37

Type Values Removed Values Added
First Time Hutool
Hutool hutool
CPE cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*
References () https://github.com/chinabugotech/hutool/issues/3994 - () https://github.com/chinabugotech/hutool/issues/3994 - Exploit, Patch, Issue Tracking

26 Sep 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-77

25 Sep 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-25 23:15

Updated : 2025-10-03 18:37


NVD link : CVE-2025-56769

Mitre link : CVE-2025-56769

CVE.ORG link : CVE-2025-56769


JSON object : View

Products Affected

hutool

  • hutool
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')