Skip to finding
important · RCE — JimuReport

JimuReport 2.5.1’s no-login export path turns a forged fixed-key signature into server-side command execution.

Affects

JimuReport, a Java/Spring Boot web-based reporting and dashboard server.

A caller needs a valid report identifier but no account, then uses the hard-coded signing secret to reach Aviator evaluation and escape its sandbox.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026