SpagoBI Command Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A command injection vulnerability has been identified in SpagoBI version 3.5.1. This issue arises in the script input feature, where an authenticated user can execute arbitrary code on the server. The vulnerability is exploited by writing a Groovy script that executes operating system commands, potentially leading to unauthorized access or manipulation of the server.

Impact

Exploitation of this vulnerability allows authenticated users with script-writing privileges to execute arbitrary code on the server, potentially leading to a complete compromise of the affected system.

Reproduction

To reproduce this vulnerability, log into the SpagoBI web application with an account that has permission to write scripts. Navigate to the script insertion panel and select Groovy as the programming language. Insert a script that executes an OS command, such as one that sends a request to an external IP address. After testing the script execution, a reverse shell can be established.

Remediation

Users are advised to disable the script input feature and update to the latest version of SpagoBI.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
10.0
exploitability
6.1
remediation
8.3
relevance
0.0
threat
6.7
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.