Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.

Project Subscriptions

Vendors Products
Adfinis Subscribe
Document Merge Service Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2170 Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
Github GHSA Github GHSA GHSA-v5gf-r78h-55q6 document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-04T19:40:11.164Z

Reserved: 2024-06-05T20:10:46.497Z

Link: CVE-2024-37301

cve-icon Vulnrichment

Updated: 2024-08-02T03:50:56.118Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-11T19:16:07.890

Modified: 2026-02-04T20:16:02.377

Link: CVE-2024-37301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses