A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
{
"cwe_ids": [
"CWE-74"
],
"github_reviewed_at": "2026-04-14T20:04:38Z",
"nvd_published_at": "2026-04-12T10:16:01Z",
"severity": "LOW",
"github_reviewed": true
}