CVE-2025-56769: Hutool

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.

Affected products

  • Hutool Hutool: before 5.8.40 (fixed in 5.8.40)

Published 2025-09-25. Last modified 2026-06-17.