Junglewise Threat Intelligence

CVE-2026-6125: Dromara warm-flow SpEL injection in Workflow Definition Handler

CVE-2026-6125 · Severity: medium · CVSS 6.3 · Published 2026-04-12

Vendors: Dromara, Maven.

Executive brief

Warm-Flow is a lightweight workflow engine used to manage business processes like approvals and task assignments. A security vulnerability allows users with workflow design privileges to inject malicious code into workflow definitions. If exploited, an attacker could execute unauthorized commands on the server, potentially leading to a full system takeover or data theft.

Technical details

A SpEL (Spring Expression Language) injection vulnerability exists in Dromara Warm-Flow versions up to 1.8.4. The flaw is located in the SpelHelper.parseExpression function within the Workflow Definition Handler component. By manipulating the listenerPath, skipCondition, or permissionFlag arguments via the /warm-flow/save-json endpoint, a remote attacker with low privileges (workflow design rights) can execute arbitrary Java code. This occurs because user-supplied expressions are parsed without sufficient validation or sandboxing. The vulnerability has been addressed in version 1.8.5.

Affected products

  • Dromara warm-flow-plugin-modes-sb < 1.8.5
  • Dromara warm-flow <= 1.8.4

Timeline

  • 2026-03-31: disclosed: Issue reported on Gitee
  • 2026-04-12: advisory: NVD and GitHub Advisory published
  • 2026-04-14: patched: GitHub Advisory reviewed and patch confirmed in 1.8.5

References