CyberRota Analysis
AI-GeneratedFastjson versions 1.2.68 to 1.2.83 are susceptible to a critical remote code execution vulnerability that can be exploited without requiring AutoType enablement or any classpath gadgets, making it particularly dangerous in its default configuration. Organizations using these versions should prioritize immediate patching or mitigation strategies to prevent potential exploitation, as attackers can execute arbitrary code remotely. This vulnerability poses a significant risk to any application relying on fastjson for JSON processing.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.