Impact
A flaw in RuoYi‑Vue‑Plus 6.0.0’s FlwTaskController.java, FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, lets an attacker remotely trigger the POST /workflow/task/completeTask endpoint to run arbitrary code on the host. The vulnerability stems from an improper restriction of trusted callers, allowing malicious input to bypass intended security checks and invoke code execution. The impact is the loss of integrity and confidentiality of the affected system, with the potential for full system compromise.
Affected Systems
The affected product is the enterprise open‑source framework RuoYi‑Vue‑Plus, version 6.0.0. No other vendors or product names are listed.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, reflecting a strong potential for unilateral exploitation. The EPSS score of < 1% indicates a very low probability that the vulnerability will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating that it has not yet been confirmed as widely exploited. Attackers can exploit the flaw remotely by crafting a request to the /workflow/task/completeTask endpoint, which requires network connectivity to the application’s API layer. Based on the description, no special local privileges or physical access are required, making the threat vector purely remote.
OpenCVE Enrichment