logo

Apache Commons Text Remote Code Execution Vulnerability

ID: 65e10050-a3d5-592e-a8d2-7d28ec2e51ee

STIX ID: report--65e10050-a3d5-592e-a8d2-7d28ec2e51ee

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

Apache Commons Text (versions 1.5–1.9) contains a critical remote code execution vulnerability (CVE-2022-42889, aka Text4Shell/Act4Shell) in the StringSubstitutor interpolator that permits attacker-supplied lookups (e.g., script, dns, url) to execute arbitrary code; a public PoC demonstrates command execution, the vendor recommends upgrading to 1.10.0 (which disables the dangerous interpolators), and Zscaler has deployed protections to detect exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.