Executive brief
A security vulnerability exists in xxl-job-admin, a popular distributed task scheduling framework. An attacker can trick a logged-in administrator into visiting a malicious website, which then silently forces the administrator's browser to modify internal automation scripts. This could allow an attacker to execute unauthorized commands on the server, potentially leading to a full system takeover or data theft.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application (specifically version 3.0.0 and versions prior to 3.4.0). The root cause is a lack of proper CSRF token validation on the '/jobcode/save' endpoint, combined with a permissive request mapping that accepts arbitrary HTTP methods. An attacker can exploit this by inducing an authenticated administrator to interact with a malicious webpage, which then submits a hidden form to the vulnerable endpoint. This allows the attacker to overwrite Glue IDE shell scripts with malicious code, leading to Remote Code Execution (RCE) when the scheduled job is next triggered.
Affected products
- xxl-job xxl-job-admin 3.0.0, versions prior to 3.4.0
Timeline
- 2026-07-15: advisory: NVD publication date
- 2026-07-15: disclosed: Public disclosure of vulnerability and PoC by Ibrahim Sartawi