CVE-2025-66916

CRITICAL

Dromara Ruoyi-vue-plus < 5.5.1 - Code Injection

Title source: rule
STIX 2.1

Description

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

Scores

CVSS v3 9.4
EPSS 0.0008
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
dromara/ruoyi-vue-plus < 5.5.1
Published Jan 08, 2026
Tracked Since Feb 18, 2026