PT-2026-32157 · Unknown · Dromara Warm-Flow

Anch0R

·

Published

2026-04-12

·

Updated

2026-04-12

·

CVE-2026-6125

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dromara warm-flow versions up to 1.8.4
Description A security flaw exists in Dromara warm-flow up to version 1.8.4. The issue resides in the SpelHelper.parseExpression function within the /warm-flow/save-json file of the Workflow Definition Handler component. Manipulation of the listenerPath, skipCondition, and permissionFlag arguments can lead to code injection. The attack can be performed remotely, and an exploit has been publicly released.
Recommendations Update to a version later than 1.8.4.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6125
GHSA-822V-8W6H-5JXP

Affected Products

Dromara Warm-Flow