CRITICALMaven

Conductor vulnerable to OS command injection through unrestricted access to Java classes

Conductor vulnerable to OS command injection through unrestricted access to Java classes

CVE-2025-26074Published 1 year agoUpdated 5 days agoSource: OSV

Affected packages

  • org.conductoross:conductor-corebefore 3.21.13

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Conductor vulnerable to OS command injection through unrestricted access to Java classes | HackTribune