Impact
Aetopia Digital Asset Management 1.0.0 contains a server‑side template injection flaw in the Add/Update Project API that permits an attacker to supply malicious content in the name or description fields. The templating engine renders that input, leading to arbitrary code execution on the host system, which can compromise the asset repository and affect confidentiality, integrity, and availability.
Affected Systems
The sole affected product is Aetopia Digital Asset Management version 1.0.0. No other vendors or product versions are listed. Patch status is not publicly documented.
Risk and Exploitability
The vulnerability permits code execution on the server. The CVSS score is 9.8 and the EPSS score of less than 1% indicates a very low probability of exploitation, and it is not listed in CISA KEV. Attackers would need remote access to the Add/Update Project endpoint. The available description does not specify authentication requirements, so that is currently unknown. Without a public exploit, the immediate threat is limited, but the impact remains severe if encountered.
OpenCVE Enrichment