CVE-2025-63721
HummerRisk
<=1.5.0
HummerRisk is an opensource cloud-native security platform.
Insecure Deserialization.
HummerRisk thru 1.5.0 is using a vulnerable Snakeyaml component allowing attackers to achieve RCE and take over the server.
Snakeyaml 1.33 is vulnerable.
Install and start hummerrisk.
Login as admin. {"username":"admin","password":"hummer","authenticate":"LOCAL"}
Create a normal user as the attacker.
Login as "hacker".
Read API-DOC.
Write files successfully! The payload is shown in the figure.
Overwrite /etc/crontab can lead to RCE.










