mediumCVSS 7.3Vulnerability

CVE-2026-5739

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
medium
summary
PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injection
epss_score
0.00388
cvss_score
7.3
ghsa_published
2026-04-07T21:32:40Z
source_url
https://github.com/advisories/GHSA-wpwf-v25w-54g3
ghsa_updated
2026-04-08T19:52:45Z
ghsa_id
GHSA-wpwf-v25w-54g3
cve_id
CVE-2026-5739
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.32287

Related Entities (5)

VULNERABLE_TO (1)

[Software]maven/tech.powerjob:powerjob-server-starter

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]maven/tech.powerjob:powerjob-server-starter

Explore deeper with Ninja Signal's threat intelligence graph