Impact
AntFlow V2.0.0 contains a flaw in ActivitiTest.java that allows a user to supply JUEL expressions directly to the application without any input validation. When interpreted, the expression can invoke operating‑system commands, enabling arbitrary code execution on the host running AntFlow. This weakness results in full compromise of the affected machine, granting an attacker complete control over the system’s confidentiality, integrity, and availability.
Affected Systems
The vulnerability is present in AntFlow version 2.0.0. No other vendor or product information is listed in the CNA data, but the issue was discovered in the source for this specific release.
Risk and Exploitability
Because the vulnerability permits execution of arbitrary OS commands, the potential impact is severe. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the lack of input filtering suggests that an attacker who can influence the JUEL expression—whether remotely through application exposure or locally with application access—could exploit the flaw. The CVSS score was not supplied, but the nature of the flaw indicates a high likelihood of exploitation if the application is reachable.
OpenCVE Enrichment