High severity8.8OSV Advisory· Published Dec 8, 2025· Updated Jun 17, 2026
CVE-2025-63721
CVE-2025-63721
Description
HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby achieve RCE and take over the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v0.1.0, v0.1.1, v0.1.2, …+ 2 more
- (no CPE)range: v0.1.0, v0.1.1, v0.1.2, …
- cpe:2.3:a:hummerrisk:hummerrisk:*:*:*:*:*:*:*:*range: <=1.5.0
- (no CPE)range: <=1.5.0
Patches
Vulnerability mechanics
References
2- gist.github.com/k1ng0fic3/e8c8c9353fff8fa95e2c2952587e9266nvdExploitThird Party Advisory
- github.com/k1ng0fic3/secrisk/blob/main/README.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.