Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2170 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed. |
Github GHSA |
GHSA-v5gf-r78h-55q6 | document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 04 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T19:40:11.164Z
Reserved: 2024-06-05T20:10:46.497Z
Link: CVE-2024-37301
Updated: 2024-08-02T03:50:56.118Z
Status : Awaiting Analysis
Published: 2024-06-11T19:16:07.890
Modified: 2026-02-04T20:16:02.377
Link: CVE-2024-37301
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA