Executive brief
Xuxueli xxl-job is a distributed job scheduling framework used to automate task execution across systems. A code injection vulnerability in the Groovy class loader allows remote attackers to execute arbitrary code, enabling full system compromise including data theft, malware installation, and operational disruption.
Technical details
The vulnerability is a code injection flaw in the GroovyClassLoader.parseClass function within GlueFactory.java. An attacker can inject malicious Groovy code that gets parsed and executed during class loading, leading to remote code execution. The attack is network-accessible and does not require authentication. Exploitation has been publicly disclosed with proof-of-concept code available; the vendor has not responded to early disclosure notifications. A patch status is not explicitly confirmed in the advisory.
Affected products
- Xuxueli xxl-job up to 3.4.2
Timeline
- 2026-09-13: disclosed
- other: Public proof-of-concept exploit available