PT-2025-30044 · Xxl-Job · Xxl-Job

Zast.Ai

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-7787

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xxl-job versions up to 3.1.1
Description A critical issue exists in xxl-job. The httpJobHandler function within the srcmainjavacomxxljobexecutorservicejobhandlerSampleXxlJob.java file is susceptible to server-side request forgery (SSRF). This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations xxl-job versions prior to 3.1.1: Update to a version beyond 3.1.1. xxl-job version 3.1.1: Update to a version beyond 3.1.1.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-7787
GHSA-F8VW-8VGH-22R9

Affected Products

Xxl-Job