{"id":"GHSA-3f8c-8h8v-p54h","summary":"snail-job is vulnerable to Code Injection through QLExpressEngine.doEval function","details":"A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results in injection. The attack can be launched remotely. Upgrading to version 1.7.0-beta1 addresses this issue. The patch is identified as 978f316c38b3d68bb74d2489b5e5f721f6675e86. The affected component should be upgraded.","aliases":["CVE-2025-14674"],"modified":"2025-12-16T01:11:16.212860Z","published":"2025-12-14T18:31:30Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-12-16T00:45:18Z","nvd_published_at":"2025-12-14T18:15:43Z","cwe_ids":["CWE-74"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14674"},{"type":"WEB","url":"https://gitee.com/aizuda/snail-job/commit/978f316c38b3d68bb74d2489b5e5f721f6675e86"},{"type":"WEB","url":"https://gitee.com/aizuda/snail-job/issues/ICNUG0"},{"type":"WEB","url":"https://gitee.com/aizuda/snail-job/issues/ICNUG0#note_44321424_link"},{"type":"WEB","url":"https://gitee.com/aizuda/snail-job/releases/tag/vsj1.7.0-beta1"},{"type":"PACKAGE","url":"https://github.com/aizuda/snail-job"},{"type":"WEB","url":"https://vuldb.com/?ctiid.336403"},{"type":"WEB","url":"https://vuldb.com/?id.336403"}],"affected":[{"package":{"name":"com.aizuda:snail-job","ecosystem":"Maven","purl":"pkg:maven/com.aizuda/snail-job"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0-beta1"}]}],"versions":["1.0.0","1.0.0-beta1","1.0.0-beta2","1.0.0-beta2.1","1.0.0-beta3","1.0.0-solon","1.0.1","1.1.0","1.1.0-beta1","1.1.0-beta2","1.1.0-jdk8-beta1","1.1.1","1.1.2","1.2.0","1.2.0-beta1","1.2.0-beta1.1","1.2.0-beta2","1.2.0-jdk8","1.2.0-jdk8-beta1","1.2.0-jdk8-beta2.1","1.3.0","1.3.0-beta1","1.3.0-beta1-jdk8","1.3.0-beta1.1","1.3.0-beta1.1-jdk8","1.3.0-beta1.2-jdk8","1.3.0-beta2","1.3.0-jdk8","1.4.0","1.4.0-beta1","1.4.0-beta1-jdk8","1.4.0-beta2","1.4.0-jdk8","1.5.0","1.5.0-beta1","1.5.0-beta1-jdk8","1.5.0-jdk8","1.6.0","1.6.0-beta1","1.6.0-beta1-jdk8","1.6.0-jdk8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-3f8c-8h8v-p54h/GHSA-3f8c-8h8v-p54h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}