{"id":"GHSA-j7j9-5253-f7vh","summary":"Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users","details":"### Summary\n\nMultiple classes evaluate Spring Expression Language (SpEL) expressions from user-supplied input using `StandardEvaluationContext`, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and credential exfiltration.\n\n### Impact\n\nAn attacker with ADMIN credentials can:\n- **Execute arbitrary OS commands** via `T(java.lang.Runtime).getRuntime().exec('...')`\n- **Exfiltrate all environment variables** (database passwords, API keys, Keycloak secrets) via `T(java.lang.System).getenv()`\n- **Read JVM system properties** via `T(java.lang.System).getProperties()`\n- **Load arbitrary classes** via `T(java.lang.Class).forName('...')`\n\n### Affected Components\n\n**1. DocumentMigrationService** (since 12.0.0)\n\nExploitable through the document migration REST API:\n- `POST /api/management/v1/document-definition/migrate`\n- `POST /api/management/v1/document-definition/migration/conflicts`\n\nThe malicious SpEL expression is supplied in the `source` or `target` field of a `DocumentMigrationPatch` object in the request body, using the `${...}` template syntax.\n\n- In 12.x: `com.ritense.document.service.DocumentMigrationService#handleSpelExpression` (document module)\n- In 13.x: same class, moved to the case module\n\n**2. Condition** (since 13.4.0)\n\nExploitable through any admin-configured widget, dashboard, or feature that uses the `Condition` framework. The SpEL expression is supplied in the `value` field of a condition's JSON configuration.\n\n- `com.ritense.valtimo.contract.conditions.Condition#resolveValue` (contract module)\n\nThis component has a significantly wider attack surface than DocumentMigrationService, as conditions are used across many modules.\n\n### Remediation\n\nReplace `StandardEvaluationContext` with `SimpleEvaluationContext` in both affected classes, which disallows Java type references and arbitrary method invocation:\n\n```kotlin\nval evaluationContext = SimpleEvaluationContext\n    .forPropertyAccessors(MapAccessor(), jsonPropertyAccessor)\n    .build()\n```","aliases":["CVE-2026-42555"],"modified":"2026-09-10T03:50:47.256568521Z","published":"2026-05-06T21:41:44Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-06T21:41:44Z","nvd_published_at":"2026-05-14T17:16:21Z","cwe_ids":["CWE-94"]},"references":[{"type":"WEB","url":"https://github.com/valtimo-platform/valtimo/security/advisories/GHSA-j7j9-5253-f7vh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42555"},{"type":"PACKAGE","url":"https://github.com/valtimo-platform/valtimo"}],"affected":[{"package":{"name":"com.ritense.valtimo:document","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/document"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.0.0"},{"fixed":"12.32.0"}]}],"versions":["12.0.0.RELEASE","12.0.1.RELEASE","12.1.0.RELEASE","12.1.1.RELEASE","12.1.2.RELEASE","12.1.3.RELEASE","12.10.0.RELEASE","12.10.1.RELEASE","12.10.2.RELEASE","12.11.0.RELEASE","12.12.0.RELEASE","12.13.0.RELEASE","12.13.1.RELEASE","12.14.0.RELEASE","12.14.1.RELEASE","12.15.1.RELEASE","12.16.0.RELEASE","12.16.1.RELEASE","12.17.0.RELEASE","12.17.1.RELEASE","12.18.0.RELEASE","12.19.0.RELEASE","12.2.0.RELEASE","12.2.1.RELEASE","12.20.0.RELEASE","12.20.1.RELEASE","12.21.0.RELEASE","12.21.1.RELEASE","12.22.0.RELEASE","12.23.0.RELEASE","12.23.1.RELEASE","12.24.0.RELEASE","12.25.0.RELEASE","12.26.0.RELEASE","12.27.0.RELEASE","12.28.0.RELEASE","12.28.1.RELEASE","12.29.0.RELEASE","12.3.0.RELEASE","12.3.1.RELEASE","12.30.0.RELEASE","12.31.0.RELEASE","12.4.0.RELEASE","12.4.1.RELEASE","12.4.3.RELEASE","12.5.0.RELEASE","12.5.1.RELEASE","12.6.0.RELEASE","12.6.1.1.RC","12.6.1.RELEASE","12.7.0.RELEASE","12.7.1.RELEASE","12.7.2.RELEASE","12.7.3.RELEASE","12.8.0.RELEASE","12.9.0.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j7j9-5253-f7vh/GHSA-j7j9-5253-f7vh.json"}},{"package":{"name":"com.ritense.valtimo:case","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/case"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.0.0"},{"fixed":"13.23.0"}]}],"versions":["13.0.0.RELEASE","13.0.1.RELEASE","13.0.2.RELEASE","13.1.0.RELEASE","13.1.1.RELEASE","13.1.2.RELEASE","13.1.3.RELEASE","13.10.0.RELEASE","13.11.0.RELEASE","13.12.0.RELEASE","13.13.0.RELEASE","13.14.0.RELEASE","13.15.0.RELEASE","13.16.0.RELEASE","13.17.0.RELEASE","13.17.1.RELEASE","13.18.0.RELEASE","13.19.0.RELEASE","13.2.0.RELEASE","13.2.1.RELEASE","13.20.0.RELEASE","13.21.0.RELEASE","13.22.0.RELEASE","13.3.0.RELEASE","13.4.0.RELEASE","13.4.1.RELEASE","13.4.2.RELEASE","13.5.0.RELEASE","13.5.1.RELEASE","13.6.0.RELEASE","13.7.0.RELEASE","13.8.0.RELEASE","13.9.0.RELEASE","13.9.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j7j9-5253-f7vh/GHSA-j7j9-5253-f7vh.json"}},{"package":{"name":"com.ritense.valtimo:contract","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/contract"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.4.0"},{"fixed":"13.23.0"}]}],"versions":["13.10.0.RELEASE","13.11.0.RELEASE","13.12.0.RELEASE","13.13.0.RELEASE","13.14.0.RELEASE","13.15.0.RELEASE","13.16.0.RELEASE","13.17.0.RELEASE","13.17.1.RELEASE","13.18.0.RELEASE","13.19.0.RELEASE","13.20.0.RELEASE","13.21.0.RELEASE","13.22.0.RELEASE","13.4.0.RELEASE","13.4.1.RELEASE","13.4.2.RELEASE","13.5.0.RELEASE","13.5.1.RELEASE","13.6.0.RELEASE","13.7.0.RELEASE","13.8.0.RELEASE","13.9.0.RELEASE","13.9.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j7j9-5253-f7vh/GHSA-j7j9-5253-f7vh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}