Injection Vulnerability in Dynamic Datasource by Baomidou
CVE-2026-7045

5.3MEDIUM

Key Information:

Vendor

Baomidou

Vendor
CVE Published:
26 April 2026

What is CVE-2026-7045?

A vulnerability exists in Baomidou Dynamic Datasource 2.5.0, specifically within the DsSpelExpressionProcessor#doDetermineDatasource function, located in the dynamic-datasource-spring component. This vulnerability allows for remote injection attacks due to improper handling of expressions in the StandardEvaluationContext/SpelExpressionParser. As a result, attackers may exploit this flaw to execute unauthorized commands or manipulate data. To mitigate this risk, it is crucial to apply the recommended patch immediately.

Affected Version(s)

dynamic-datasource 2.5.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Winegee (VulDB User)
.