A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 90.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 90.00 |
VPI formula vpi-v1