An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configurationReferenceshttps://dev.mysql.com/doc/connector-j/en/connector-j-connprops-interceptor-classes-and-interfaces.htmlhttps://github.com/xiaoxiaoranxxx/CVE-2025-70828