CVE-2025-5680 | Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0 Groovy Script SysScriptController.java executeScript script deserialization (ICAPT5 / EUVD-2025-17026)
A vulnerability, which was classified as critical, was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. This impacts the function executeScript of the file /src/main/java/com/dstz/sys/rest/controller/SysScriptController.java of the component Groovy Script Handler. The manipulation of the argument script results in deserialization.
This vulnerability is identified as CVE-2025-5680. The attack can be executed remotely. Additionally, an exploit exists.