GHSA-m9q4-p56m-mc6q
GitHub Security Advisory
Apache DolphinScheduler: RCE by arbitrary js execution
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
Affected Packages
Maven
org.apache.dolphinscheduler:dolphinscheduler
Affected versions:
0
(fixed in 3.2.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.