PT-2026-80321 · Pypi · Document Merge Service
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Impact
A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the
xltpl library uses a npn-sandboxed Jinja environment for the processing of the template.Patches
It has been patched in v9.1.0
Workarounds
Disable the upload/usage of XLSX templates.
References
Are there any links users can visit to find out more?
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Document Merge Service