Description
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
Published: 2024-06-11
Score: 7.2 High
EPSS: 5.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2170 Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
Github GHSA Github GHSA GHSA-v5gf-r78h-55q6 document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
History

Wed, 04 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Adfinis Document Merge Service
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-04T19:40:11.164Z

Reserved: 2024-06-05T20:10:46.497Z

Link: CVE-2024-37301

cve-icon Vulnrichment

Updated: 2024-08-02T03:50:56.118Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-11T19:16:07.890

Modified: 2026-02-04T20:16:02.377

Link: CVE-2024-37301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses