References https://nvd.nist.gov/vuln/detail/CVE-2025-34040 https://github.com/advisories/GHSA-mxx7-67f4-p53j https://vulncheck.com/advisories/zhiyuan-oa-system-path-traversal-file-upload https://www.exploit-db.com/exploits/52490 https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E5%AF%BC%E8%87%B4RCE(CVE-2025-34040).md https://www.cnblogs.com/pursue-security/p/17677130.html https://www.sentinelone.com/vulnerability-database/cve-2025-34040/ https://service.seeyon.com/patchtools/tp.html#/patchList?type=%E5%AE%89%E5%85%A8%E8%A1%A5%E4%B8%81&id=1
Related VulnerabilitiesPoCCVE-2025-34040: Zhiyuan OA Platform - Arbitrary File UploadPoCCNVD-2020-62422: 致远oa系统存在任意文件读取漏洞Spring Kafka CVE-2023-34040 不安全的反序列化漏洞