CVE-2026-6125
Last modified
CVE-2026-6125 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6125?
How severe is CVE-2026-6125?
How do I fix CVE-2026-6125?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-61244Vulnerability in the PeopleSoft Enterprise FIN Manufacturing…9.1
- CVE-2026-61245Vulnerability in the PeopleSoft Enterprise FIN Manufacturing…9.8
- CVE-2026-61246Vulnerability in the Oracle Platform Security for Java produ…8.8
- CVE-2026-61247Vulnerability in the Oracle Workflow product of Oracle E-Bus…4.8
- CVE-2026-61248Vulnerability in the Oracle Internet Directory product of Or…9.9
- CVE-2026-61249Vulnerability in the Oracle Learning Management product of O…6.5
- CVE-2026-61250Vulnerability in the Oracle Payroll product of Oracle E-Busi…6.5
- CVE-2026-61251Vulnerability in the HRMS (Australia) product of Oracle E-Bu…6.5
- CVE-2026-61252Vulnerability in the Oracle HRMS (Hong Kong) product of Orac…5.4
- CVE-2026-61253Vulnerability in the Oracle HRMS (Japanese) product of Oracl…5.4
- CVE-2026-61254Vulnerability in the Oracle HRMS (Republic of Korea) product…5.4
- CVE-2026-61255Vulnerability in the Oracle HRMS (New Zealand) product of Or…5.4
Are you affected by CVE-2026-6125?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
