---
id: CVE-2025-63402
title: >-
  An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a
  remote attacker to execute arbitrary code via APIs do not enforcing limits on
  the number or size of requests
summary: >-
  An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a
  remote attacker to execute arbitrary code via APIs do not enforcing limits on
  the number or size of requests
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L'
cwe:
  - CWE-770
vendor: hcltech
product: dragon
affected:
  - dragon < 7.6.0
patched:
  - dragon 7.6.0
published: '2025-12-03'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-63402'
references:
  - url: >-
      https://excalibur-hcl.my.salesforce.com/sfc/p/#U0000000YO14/a/Pf000003dyVd/ckzaFpdm68dwd1nWqgtLfXHp3Pim_YwLUI4WcRB__Ng
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00328
epssPercentile: 0.23127
ingestedAt: '2026-07-06T16:44:34.464Z'
---

## Overview

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests

## Affected

- `dragon < 7.6.0`

## Remediation

Upgrade past the affected range:

- `dragon 7.6.0`
