Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91145— Activiti through 7.1.0.M6 Expression Injection via Mail Task

Quick assessment

Affected
Activiti Activiti
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Activiti 7.1.0.M6 及以下版本未能验证流程变量中的“hash-brace”延迟表达式(即形如 的 Spring 表达式),从而允许攻击者绕过表达式过滤机制。攻击者可以注入以 开头的表达式,这些表达式会被存储起来,并在邮件任务使用变量驱动的内容字段时,在完整的 Spring 上下文中被求值,进而实现对应用程序 Bean 的方法调用。

CVSS 7.1 · High EPSS 0.24% · P16

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Activiti Activiti ≤ 7.1.0.M6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91145

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Activiti through 7.1.0.M6 Expression Injection via Mail Task
Source: CVE Program / CVE List V5
Vulnerability Description
Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
表达式语言语句中使用的特殊元素转义处理不恰当(表达式语言注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Activiti Activiti 0 ~ 7.1.0.M6 -

II. Public POCs for CVE-2026-91145

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91145

登录查看更多情报信息。

Vendor Advisories for CVE-2026-91145 (1)

Security Blog Posts for CVE-2026-91145 (1)

Vendor Pages for CVE-2026-91145 (2)

Other References for CVE-2026-91145 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91145

No comments yet


Leave a comment