Medium severity6.5NVD Advisory· Published Sep 25, 2025· Updated Jun 17, 2026
CVE-2025-56769
CVE-2025-56769
Description
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cn.hutool:hutool-extraMaven | < 5.8.40 | 5.8.40 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/chinabugotech/hutool/issues/3994nvdExploitIssue TrackingPatchWEB
- github.com/advisories/GHSA-gcfh-36x4-mgj6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-56769ghsaADVISORY
- github.com/chinabugotech/hutool/commit/3d0d8dea4bc2fac2e9b45dc67244195f30e42e4bghsaWEB
News mentions
0No linked articles in our index yet.