CVE-2026-5739 is a code injection vulnerability in PowerJob 5.1.0/5.1.1/5.1.2's OpenAPI Endpoint. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. [truncated]
A SQL injection vulnerability was identified in PowerJob versions 5.1.0, 5.1.1, and 5.1.2. The vulnerability is located in the detailPlus endpoint of the InstanceController. The manipulation of the customQuery argument leads to SQL injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability ha [truncated]