CVE-2025-70974 is a critical vulnerability in Fastjson versions prior to 1.2.48, stemming from an incomplete fix for a previous issue. It allows for JNDI injection due to improper handling of the @type key in JSON documents, potentially leading to remote code execution. This vulnerability has a CVSS score of 10.0 (CRITICAL) with a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The flaw has been actively exploited in the wild between 2023 and 2025, and while no public exploit code is listed, it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.2.48CPE match | cpe:2.3:a:alibaba:fastjson:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.