CVE-2025-66916

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/01/2026
Last modified:
30/01/2026

Description

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dromara:ruoyi-vue-plus:*:*:*:*:*:*:*:* 5.5.1 (including)