GHSA-9wq6-87hw-6mhc
Dashboard / Vulnerabilities / GHSA-9wq6-87hw-6mhc
Summary: PowerJob OpenAPIController is missing authorization
Details: A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
References: https://nvd.nist.gov/vuln/detail/CVE-2025-11581, https://github.com/PowerJob/PowerJob/issues/1128, https://github.com/PowerJob/PowerJob, https://vuldb.com/?ctiid.327903, https://vuldb.com/?id.327903, https://vuldb.com/?submit.662558
Affected packages
Package
Name: tech.powerjob:powerjob-server-starter
Purl: pkg:maven/tech.powerjob/powerjob-server-starter
Affected ranges
Type: ECOSYSTEM
Events:
