Executive brief
Beetl is a high-performance Java template engine used to generate dynamic web pages and documents. A security vulnerability exists in its Spring integration component that allows attackers to inject malicious code through expression language statements. If exploited, this could allow an attacker to execute unauthorized commands or access sensitive data on the server, potentially leading to a full system compromise.
Technical details
A vulnerability classified as CWE-917 (Expression Language Injection) exists in the SpELFunction extension of Beetl up to version 3.20.2.RELEASE. The issue is located in the `SpELFunction.java` file within the `beetl-spring-classic` integration module. When the SpELFunction is registered and used to process user-controllable input without proper neutralization, an attacker can inject malicious SpEL expressions. This can be exploited remotely over the network without authentication to achieve arbitrary code execution or unauthorized data access. As of the advisory date, no official patch has been released by the maintainer.
Affected products
- xiandafu (com.ibeetl) beetl-spring-classic <= 3.20.2.RELEASE
Timeline
- 2026-04-15: disclosed: Issue reported to the project maintainer via Gitee.
- 2026-05-17: advisory: Vulnerability published in NVD and GitHub Advisory Database.