A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
提示
摘要
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/AT190510-Cuong/CVE-2026-38165-SSTI-
- https://github.com/opensagres/xdocreport
- https://github.com/opensagres/xdocreport/pull/723
- https://hackmd.io/@cuongnh/H1sB1RIy-g
- https://hackmd.io/@cuongnh/SyPn-XF0ll
时间线
- nvd_ingest NVD