CVE-2026-88616: RuoYi-Vue-Plus vulnerability
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components
Affected Software
Event History
Frequently Asked Questions
Which application versions are confirmed affected?
The available data identifies RuoYi-Vue-Plus version 6.0.0 as affected. It does not establish whether earlier or later versions are vulnerable.
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable through workflow task completion and related components. The available data does not specify whether authentication, workflow permissions, or other prerequisites are required.
Which endpoint or code paths should defenders prioritize for investigation?
Prioritize the POST /workflow/task/completeTask endpoint and the FlwTaskController.java, FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, and Warm-Flow TaskService.skip code paths. Review requests to the task-completion endpoint and associated workflow execution activity for unexpected code execution behavior.