PT-2026-32157 · Dromara · Warm-Flow

Anch0R

·

Published

2026-04-12

·

Updated

2026-04-12

·

CVE-2026-6125

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6125

Affected Products

Warm-Flow