CVE-2025-66916

CRITICAL

dromara ruoyi-vue-plus < 5.5.1 - Arbitrary File Read and Write via QLExpress Expression Injection

Title source: llm
STIX 2.1

Description

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

Scores

CVSS v3 9.4
EPSS 0.0063
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
dromara/ruoyi-vue-plus < 5.5.1
Published Jan 08, 2026
Tracked Since Feb 18, 2026