{"id":"GHSA-822v-8w6h-5jxp","summary":"Warm-Flow has a SpEL Expression Injection in SpelHelper.parseExpression","details":"A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.","aliases":["CVE-2026-6125"],"modified":"2026-04-14T20:34:14.497992Z","published":"2026-04-12T12:30:26Z","database_specific":{"cwe_ids":["CWE-74"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-04-14T20:04:38Z","nvd_published_at":"2026-04-12T10:16:01Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6125"},{"type":"WEB","url":"https://gitee.com/dromara/warm-flow"},{"type":"WEB","url":"https://gitee.com/dromara/warm-flow/issues/IHURVQ"},{"type":"WEB","url":"https://gitee.com/dromara/warm-flow/pulls/387"},{"type":"PACKAGE","url":"https://github.com/dromara/warm-flow"},{"type":"WEB","url":"https://vuldb.com/submit/793322"},{"type":"WEB","url":"https://vuldb.com/vuln/356989"},{"type":"WEB","url":"https://vuldb.com/vuln/356989/cti"}],"affected":[{"package":{"name":"org.dromara.warm:warm-flow-plugin-modes-sb","ecosystem":"Maven","purl":"pkg:maven/org.dromara.warm/warm-flow-plugin-modes-sb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.5"}]}],"versions":["1.3.4","1.3.5","1.3.6","1.3.6-m1","1.3.7","1.3.7-m1","1.3.8","1.6.0","1.6.0-m1","1.6.0-m2","1.6.0-m3","1.6.0-m4","1.6.0-m5","1.6.0-m6","1.6.1","1.6.10","1.6.10-m1","1.6.6","1.6.7","1.6.7-M1","1.6.7-M2","1.6.8","1.6.9","1.7.0","1.7.0-m1","1.7.0-m2","1.7.0-m3","1.7.0-m4","1.7.1","1.7.2","1.7.3","1.7.3-m1","1.7.4","1.7.4-m1","1.7.4-m2","1.7.5","1.7.5-m1","1.7.5-m2","1.7.6","1.7.7","1.8.0","1.8.0-m1","1.8.0-m2","1.8.0-m3","1.8.1","1.8.1-m1","1.8.1-m2","1.8.2","1.8.2-m1","1.8.2-m2","1.8.2-m3","1.8.2-m4","1.8.2-m5","1.8.2-m6","1.8.3","1.8.3-m1","1.8.3-m2","1.8.3-m3","1.8.3-m4","1.8.4","1.8.4-m1","1.8.4-m2","1.8.4-m3","1.8.5-m1","1.8.5-m2","1.8.5-m3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-822v-8w6h-5jxp/GHSA-822v-8w6h-5jxp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}