VYPR

AntFlow

by AntFlow

CVEs (2)

  • CVE-2026-75414CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.

  • CVE-2026-75415HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identity credential information, thereby…