Impact
An attacker can execute arbitrary code on a DSpace server by crafting a malicious COAR Notify or LDN message that is rendered through Velocity templates. The flaw, identified as CWE‑94, allows the template engine to interpret attacker‑controlled input as executable code, potentially granting full control over the hosting environment, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects DSpace repository software. Versions from 8.0‑rc1 up to but not including 8.4, from 9.0‑rc1 up to but not including 9.3, and the release candidate 10‑rc1 are impacted. All deployments running these versions and using COAR Notify or LDN message handling expose an execution path.
Risk and Exploitability
The CVSS vector assigns a score of 8, indicating a high risk. The EPSS score is unavailable, so the current exploitation probability is unknown, and the issue is not listed in CISA’s KEV catalog. Likely attack vectors involve remote submission of malicious LDN content, requiring network access to DSpace’s notification endpoints. The flaw permits remote code execution without local privilege escalation, making it a critical threat to any exposed system.
OpenCVE Enrichment
Github GHSA