Xuxueli · Xxl-Job · CVE-2026-90488
**Name of the Vulnerable Software and Affected Versions**
Xuxueli xxl-job versions prior to 3.4.3
**Description**
A code injection flaw exists that allows for remote exploitation. The issue resides in the `GroovyClassLoader.parseClass()` function within the `xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java` file.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the `GroovyClassLoader.parseClass()` function to minimize the risk of exploitation.