CVE-2026-52439
CRITICAL
9,8
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism
917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
Java
https://gitee.com/xiandafu/beetl/issues/IJO1HM
https://gitee.com/xiandafu/beetl
https://gitee.com/xiandafu/beetl/issues/IJO1HM