CVE-2025-14856: y_project RuoYi getnames code injection
Published Dec 18, 2025
·Updated
A security vulnerability has been detected in yproject RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
2 affected components
y_project/RuoYi<=4.8.1
Ruoyi Ruoyi<=4.8.1
Event History
Dec 18, 2025
CVE Published
via MITRE·01:32 AM
Data Sourced
via MITRE·01:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Oct 20, 57967
Event
via NVD·10:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-14856?
CVE-2025-14856 is classified as a critical vulnerability due to its potential for remote code injection.
2
How do I fix CVE-2025-14856?
To fix CVE-2025-14856, upgrade y_project RuoYi to version 4.8.2 or later.
3
What systems are affected by CVE-2025-14856?
CVE-2025-14856 affects y_project RuoYi versions up to and including 4.8.1.
4
What type of attack is associated with CVE-2025-14856?
CVE-2025-14856 is associated with remote code injection attacks.
5
Can CVE-2025-14856 be exploited remotely?
Yes, CVE-2025-14856 can be exploited remotely if the vulnerable function is manipulated.