CVE-2025-26074 Information
Jul 01, 2025
cve
Description
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.
Reference
https://github.com/conductor-oss/conductor https://github.com/conductor-oss/conductor/blob/main/core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java https://medium.com/@mrcnry/cve-2025-26074-remote-code-execution-in-conductor-oss-via-inline-javascript-injection-5ce3cb651cfb
Related CNNVD
CNNVD-202506-3774 (Published: 2025-06-30)
Share on: