PT-2026-80321 · Pypi · Document Merge Service

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact

A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template.

Patches

It has been patched in v9.1.0

Workarounds

Disable the upload/usage of XLSX templates.

References

Are there any links users can visit to find out more?

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-W47Q-945M-Q9PC

Affected Products

Document Merge Service