CVE-2025-11093
8.4WSO2 · Multiple Products (Micro Integrator, API Manager, Enterprise Integrator, Universal Gateway, API Control Plane, Traffic Manager)
A code injection vulnerability in WSO2 products allows authenticated users with elevated privileges to execute arbitrary code via the GraalJS and NashornJS Script Mediator engines.
Executive summary
WSO2 products are vulnerable to arbitrary code execution, posing a critical risk to the integration runtime environment for organizations using these platforms.
Vulnerability
The flaw stems from insufficient security restrictions within the GraalJS and NashornJS Script Mediator engines. Authenticated users with administrative or API creator privileges can leverage these engines to perform unauthorized code execution within the integration runtime.
Business impact
The ability to execute arbitrary code allows an attacker to gain full control over the integration runtime, potentially leading to total system compromise, data exfiltration, or the disruption of critical API and integration services. With a CVSS score of 8.4, this vulnerability represents a high-severity threat that could lead to significant operational downtime and the loss of sensitive data processed by WSO2 middleware.
Remediation
Immediate Action: Upgrade all affected WSO2 components to the patched build versions specified in the official WSO2 security advisory (WSO2-2025-4510).
Proactive Monitoring: Review administrative audit logs for any unusual activity involving script mediator configurations or unexpected code execution patterns within the integration runtime.
Compensating Controls: Restrict administrative and API creator access to the minimum set of necessary personnel to reduce the attack surface for this authenticated-only flaw.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for full system compromise, organizations must prioritize patching these WSO2 products immediately. Security teams should verify their current build versions against the list provided in the vendor advisory and apply the necessary updates to ensure the security of their integration infrastructure.
More WSO2 CVEs
Sources
Originally found and disclosed by crnković, per the CVE Program record.