PT-2025-30047 · Xuxueli · Xxl-Job

Zast.Ai

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-7788

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xxl-job versions up to 3.1.1
Description A critical issue exists in Xuxueli xxl-job. The commandJobHandler function within the srcmainjavacomxxljobexecutorservicejobhandlerSampleXxlJob.java file is susceptible to OS command injection. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations Update to a version beyond 3.1.1. As a temporary workaround, consider restricting access to the commandJobHandler function until a patch is available.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-7788

Affected Products

Xxl-Job