Junglewise Threat Intelligence

CVE-2025-15098: YunaiV yudao-cloud SSRF in Business Process Management component

CVE-2025-15098 · Severity: medium · CVSS 6.3 · Published 2025-12-26

Technologies: YunaiV Yudao-Cloud. Vendors: YunaiV.

Executive brief

YunaiV yudao-cloud is a microservices framework used for building enterprise-level backend systems. A security flaw in its business process management component allows authorized users to force the server to make unintended network requests. This could allow an attacker to scan internal company networks, access private services not exposed to the internet, or disrupt internal operations.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Business Process Management (BPM) component of YunaiV yudao-cloud up to version 2025.11. The issue is located within the BpmHttpCallbackTrigger and BpmSyncHttpRequestTrigger functions, where insufficient validation of the url, header, and body arguments allows for request manipulation. An authenticated attacker with BPM process design permissions can exploit this to send arbitrary HTTP requests from the application server. This can be used to pivot into internal network segments or interact with internal metadata services. As of the advisory date, the vendor has not responded to disclosure attempts, and a public exploit is available.

Affected products

  • YunaiV yudao-cloud up to 2025.11

Timeline

  • 2025-12-25: disclosed: Public disclosure of the vulnerability and exploit code.
  • 2025-12-26: advisory: NVD/VulDB advisory published.

References

Related threats