dolphinschedulerGHSA-f786-9c63-8xr8
Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability
Medium6.3CVE-2025-62233 · Published Apr 24, 2026 · updated May 5, 2026
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | >= 3.2.0, < 3.3.1 | 3.3.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2025-62233
More dolphinscheduler advisories
All dolphinscheduler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 24 | Apache DolphinScheduler has an Incorrect Authorization Vulnerability | High8.1 | 3.4.1 |
| Apr 9 | Apache DolphinScheduler vulnerable to sensitive information disclosure | High7.5 | 3.2.0 |
| Sep 92025 | Apache DolphinScheduler vulnerable to Alert Script Attack | High8.8 | 3.2.2 |
| Sep 32025 | Apache DolphinScheduler Incorrect Default Permissions Vulnerability | Low | 3.3.1 |
| Aug 122024 | Apache DolphinScheduler: Resource File Read And Write Vulnerability | High8.1 | 3.2.2 |
| Aug 122024 | Apache DolphinScheduler: RCE by arbitrary js execution | High8.8 | 3.2.2 |