mediumCVSS 7.3Vulnerability

CVE-2026-8759

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special elements used in an expression language statement. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
medium
summary
Beetl's SpELFunction extension function has an expression injection risk
epss_score
0.00516
cvss_score
7.3
retrieved_at
2026-10-03T18:15:53+00:00
ghsa_published
2026-05-17T15:31:42Z
source_url
https://github.com/advisories/GHSA-fmmw-44rp-jcfp
ghsa_updated
2026-05-23T00:09:57Z
ghsa_id
GHSA-fmmw-44rp-jcfp
last_source
FIRST EPSS
cve_id
CVE-2026-8759
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.41894

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]maven/com.ibeetl:beetl-spring-classic

AFFECTS (1)

→[Software]maven/com.ibeetl:beetl-spring-classic

HAS_WEAKNESS (1)

→[Weakness]Improper Input Validation

Explore deeper with Ninja Signal's threat intelligence graph