Skip to main content

apache-druid-javascript-rce-vulnerability-analysis

Understanding the CVE in Apache Druid 0.20.0 where authenticated attackers can execute arbitrary code via JavaScript payloads. The vulnerability exploits @JacksonInject with empty key "" to override JavaScriptConfig and enable JavaScript execution even when disabled. Use this skill to understand the attack vector and plan the fix.

Jump to install

Source facts

Repository
cxcscmu/SkillLearnBench
Last source activity
April 24, 2026 at 05:14
Detected SKILL.md language
English
Stars
77
Forks
4

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.