Sandbox Escape Vulnerability in dotCMS Velocity Scripting Engine
CVE-2025-11165
9.4CRITICAL
What is CVE-2025-11165?
A vulnerability exists in dotCMS's Velocity scripting engine, which allows authenticated users with scripting privileges to bypass critical class and package restrictions. By manipulating the Velocity engine's runtime settings, an attacker can eliminate protections that prevent access to sensitive Java classes. This breach can lead to unauthorized execution of arbitrary system commands within the application environment, posing significant risks to the application's security and integrity.
Affected Version(s)
dotCMS 24.12
dotCMS 25.07
