Sandbox Escape Vulnerability in dotCMS Velocity Scripting Engine
CVE-2025-11165
9.4CRITICAL
What is CVE-2025-11165?
A vulnerability exists in dotCMS's Velocity scripting engine, which allows authenticated users with scripting privileges to bypass critical class and package restrictions. By manipulating the Velocity engine's runtime settings, an attacker can eliminate protections that prevent access to sensitive Java classes. This breach can lead to unauthorized execution of arbitrary system commands within the application environment, posing significant risks to the application's security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dotCMS 24.12
dotCMS 25.07
