Description
A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argument content results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote code execution (potential)
Action: Assess Impact
AI Analysis

Impact

A security flaw exists in the ViewEngine component of the Furion .NET Framework, specifically within the RunCompile method of ViewEngine.cs. The flaw permits an attacker to inject specially crafted content that is not properly neutralized by the template engine’s parsing, potentially allowing unintended evaluation of template expressions. The flaw is triggered by manipulating the argument content passed to RunCompile; the resulting improper neutralization of template elements may lead to unintended code execution or other undesirable behavior. The attack can be executed remotely and the exploit has been released publicly.

Affected Systems

The vulnerability affects versions of the Furion .NET Framework up to 4.9.9.95. Organizations should identify installations of this framework running those versions and determine whether they incorporate the View Engine component described above.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk, yet the exploit is publicly available and can be triggered remotely. The EPSS score is not yet available, and the vulnerability is not listed in the CISA KEV catalog. The remote nature of the attack and the availability of an exploit raise the risk. The attack vector is likely to involve sending malicious template content to endpoints that invoke RunCompile; the precise exploitation conditions are only inferred from the description.

Generated by OpenCVE AI on October 11, 2026 at 12:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version of Furion .NET Framework newer than 4.9.9.95 once an official patch is released.
  • If an immediate upgrade is not possible, manually sanitize or escape special template elements before passing them to RunCompile to prevent improper neutralization.
  • Restrict template rendering to trusted sources only, and monitor application logs for abnormal template compile activity to detect exploitation attempts.

Generated by OpenCVE AI on October 11, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argument content results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Furion .NET Framework View ViewEngine.cs RunCompile special elements in template engine
First Time appeared Furion
Furion .net Framework
Weaknesses CWE-1336
CWE-791
CPEs cpe:2.3:a:furion:.net_framework:*:*:*:*:*:*:*:*
Vendors & Products Furion
Furion .net Framework
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Furion .net Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T10:30:14.538Z

Reserved: 2026-10-10T15:14:25.303Z

Link: CVE-2026-108570

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T11:16:59.980

Modified: 2026-10-11T11:16:59.980

Link: CVE-2026-108570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T12:30:18Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine

  • CWE-791

    Incomplete Filtering of Special Elements