Sandbox Escape Vulnerability in dotCMS Velocity Scripting Engine
CVE-2025-11165

9.4CRITICAL

Key Information:

Vendor

Dotcms

Status
Vendor
CVE Published:
24 February 2026

What is CVE-2025-11165?

A vulnerability exists in dotCMS's Velocity scripting engine, which allows authenticated users with scripting privileges to bypass critical class and package restrictions. By manipulating the Velocity engine's runtime settings, an attacker can eliminate protections that prevent access to sensitive Java classes. This breach can lead to unauthorized execution of arbitrary system commands within the application environment, posing significant risks to the application's security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

dotCMS 24.12

dotCMS 25.07

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.