Running Elephant maintains a narrowly scoped product line centered on the Datart application, with a compact vulnerability footprint within this focused scope. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Running Elephant over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56819CRITICAL An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter. | Sep 24, 2025 | 9.8 | 44 | NO | YES |
CVE-2025-56816HIGH Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver | Sep 24, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-70828HIGH An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration | Feb 17, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-56815HIGH Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a pa | Sep 24, 2025 | 7.1 | 24 | NO | NO |
CVE-2025-70829MEDIUM An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string. | Feb 17, 2026 | 5.7 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Running Elephant.
Media articles that mention a CVE ID that affects a product developed by Running Elephant — matched by CVE ID, not by vendor name.