Injection Vulnerability in Dynamic Datasource by Baomidou
CVE-2026-7045
5.3MEDIUM
What is CVE-2026-7045?
A vulnerability exists in Baomidou Dynamic Datasource 2.5.0, specifically within the DsSpelExpressionProcessor#doDetermineDatasource function, located in the dynamic-datasource-spring component. This vulnerability allows for remote injection attacks due to improper handling of expressions in the StandardEvaluationContext/SpelExpressionParser. As a result, attackers may exploit this flaw to execute unauthorized commands or manipulate data. To mitigate this risk, it is crucial to apply the recommended patch immediately.
Affected Version(s)
dynamic-datasource 2.5.0
