CVE-2025-64408

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) throughuser-controllable URL parameters. These vulnerabilities affect allapplications using Causeway's ViewModel functionality and can be exploitedby authenticated attackers to execute arbitrary code with applicationprivileges.

This issue affects all current versions.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
apacheCNA
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown