PT-2025-51174 · Aizuda · Snail-Job

Published

2025-12-14

·

Updated

2025-12-15

·

CVE-2025-14674

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions aizuda snail-job versions up to 1.6.0
Description A flaw exists in the
QLExpressEngine.doEval
function within the
snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java
file. This allows for injection attacks, which can be initiated remotely. The vulnerability is addressed by upgrading to version 1.7.0-beta1, identified by the patch
978f316c38b3d68bb74d2489b5e5f721f6675e86
.
Recommendations Upgrade to version 1.7.0-beta1.

Fix

Special Elements Injection

Improper Neutralization

Weakness Enumeration

Related Identifiers

CVE-2025-14674
GHSA-3F8C-8H8V-P54H

Affected Products

Snail-Job