CVE-2025-63721

HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby achieve RCE and take over the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hummerrisk:hummerrisk:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-08 17:16

Updated : 2025-12-11 15:15


NVD link : CVE-2025-63721

Mitre link : CVE-2025-63721

CVE.ORG link : CVE-2025-63721


JSON object : View

Products Affected

hummerrisk

  • hummerrisk
CWE
NVD-CWE-noinfo CWE-502

Deserialization of Untrusted Data