On September 5, 2026, Qisanx CERT issued a security notice stating that the JimuReport (Building Report) v2.5.1 version it developed contained an unauthorized remote code execution vulnerability. This vulnerability stemmed from dual flaws in the automatic export function regarding identity verification and expression execution: attackers could forge fixed key signatures to bypass authentication and trigger the Aviator expression engine through the export interface, resulting in sandbox escape and arbitrary command execution. The PoC has been made public, with a CVSS 3.1 score of 9.8 (high risk). The impact is estimated to be on the tens of thousands of systems, and there is no need for authentication or special network conditions to exploit this vulnerability. It is recommended that customers immediately upgrade Aviator to ≥5.4.4, rotate hard-coded keys, block related interface access, and disable unauthorized parameter execution. Meanwhile, wait for the official fix version to be released.
Qianxin CERT has issued a security alert regarding the unauthorized remote code execution vulnerability in JimuReport (QVD-2026-61751). This vulnerability stems from two flaws in the automatic export function of version 2.5.1: attackers can forge fixed key signatures to bypass authentication and trigger the Aviator expression engine through the export interface, enabling sandbox escape and arbitrary command execution. The PoC has been made public, with a CVSS 3.1 score of 9.8 (high risk). The impact involves tens of thousands of systems, and there is no need for authentication or special network conditions to exploit this vulnerability. It is recommended that customers immediately upgrade Aviator to ≥5.4.4, rotate hard-coded keys, block access to related interfaces, and disable unauthorized parameter execution. Meanwhile, wait for the official fix to be released.