An issue was discovered in chinabugotech hutool before 5.8.40 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
{
"severity": "HIGH",
"cwe_ids": [
"CWE-917"
],
"github_reviewed": true,
"nvd_published_at": "2025-09-25T23:15:54Z",
"github_reviewed_at": "2025-09-26T15:14:58Z"
}