Description
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2170 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed. |
Github GHSA |
GHSA-v5gf-r78h-55q6 | document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection |
References
History
Wed, 04 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T19:40:11.164Z
Reserved: 2024-06-05T20:10:46.497Z
Link: CVE-2024-37301
Updated: 2024-08-02T03:50:56.118Z
Status : Awaiting Analysis
Published: 2024-06-11T19:16:07.890
Modified: 2026-02-04T20:16:02.377
Link: CVE-2024-37301
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA