Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
Critical severity
GitHub Reviewed
Published
May 1, 2026
in
valtimo-platform/valtimo
•
Updated May 14, 2026
Give feedback on Dependabot alerts