CVE-2026-53964

high

Description

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template. This issue has been patched in version 9.1.0.

References

https://github.com/adfinis/document-merge-service/security/advisories/GHSA-w47q-945m-q9pc

https://github.com/adfinis/document-merge-service/releases/tag/v9.1.0

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91047

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-02

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00493