Skip to content

Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users

Critical severity GitHub Reviewed Published May 1, 2026 in valtimo-platform/valtimo • Updated May 14, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts