CVE-2025-63721
EUVD-2025-20178908.12.2025, 17:16
HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby achieve RCE and take over the server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hummerrisk | hummerrisk | 𝑥 ≤ 1.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration