VYPR

Wukong_HRM

by Wukongopensource

CVEs (2)

  • CVE-2026-108707CriOct 11, 2026
    risk 0.64cvss 9.8epss —

    Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and…

  • CVE-2026-108708HigOct 11, 2026
    risk 0.57cvss 8.8epss —

    Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary…