mediumCVSS 7.3Vulnerability

CVE-2026-8759

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special elements used in an expression language statement. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
medium
summary
Beetl's SpELFunction extension function has an expression injection risk
epss_score
0.00406
cvss_score
7.3
ghsa_published
2026-05-17T15:31:42Z
source_url
https://github.com/advisories/GHSA-fmmw-44rp-jcfp
ghsa_updated
2026-05-23T00:09:57Z
ghsa_id
GHSA-fmmw-44rp-jcfp
cve_id
CVE-2026-8759
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.34143

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]maven/com.ibeetl:beetl-spring-classic

AFFECTS (1)

[Software]maven/com.ibeetl:beetl-spring-classic

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

Explore deeper with Ninja Signal's threat intelligence graph