hutool-extra is vulnerable to Remote Code Execution (RCE)
98
Critical Risk
Hutool’s ExpressionEngine interface defines the allowClassSet parameter, which is intended to restrict the Java classes that can be accessed during expression evaluation. However, the three built-in engine implementations — SpELEngine, MvelEngine, and RhinoEngine — completely ignore this parameter, allowing unrestricted access to arbitrary Java classes and methods, which can lead to remote code execution (RCE).
You are affected if you are using a version that falls within the vulnerable range and if you are using the ExpressionEngine (SpELEngine, MvelEngine, or RhinoEngine) interfaces.
hutool-extra is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 5.8.45.
Upgrade the cn.hutool:hutool-extra library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant