Executive brief
Warm-Flow is a lightweight workflow engine used to manage business processes like approvals and task assignments. A security vulnerability allows users with workflow design privileges to inject malicious code into workflow definitions. If exploited, an attacker could execute unauthorized commands on the server, potentially leading to a full system takeover or data theft.
Technical details
A SpEL (Spring Expression Language) injection vulnerability exists in Dromara Warm-Flow versions up to 1.8.4. The flaw is located in the SpelHelper.parseExpression function within the Workflow Definition Handler component. By manipulating the listenerPath, skipCondition, or permissionFlag arguments via the /warm-flow/save-json endpoint, a remote attacker with low privileges (workflow design rights) can execute arbitrary Java code. This occurs because user-supplied expressions are parsed without sufficient validation or sandboxing. The vulnerability has been addressed in version 1.8.5.
Affected products
- Dromara warm-flow-plugin-modes-sb < 1.8.5
- Dromara warm-flow <= 1.8.4
Timeline
- 2026-03-31: disclosed: Issue reported on Gitee
- 2026-04-12: advisory: NVD and GitHub Advisory published
- 2026-04-14: patched: GitHub Advisory reviewed and patch confirmed in 1.8.5