Impact
The vulnerability resides in the xiandafu Beetl template engine version 3.20.2. It allows a remote attacker to invoke the type.new function in conjunction with the property reflection mechanism to execute arbitrary code. This breach can lead to full compromise of the system executing the templated code, providing the attacker with the same privileges as the process running the engine. The weakness corresponds to CWE‑917, an improper handling of user‑provided data that results in code execution.
Affected Systems
The affected product is the open‑source template engine Beetl, provided by xiandafu, version 3.20.2. No other vendors or versions are explicitly identified as vulnerable in the current details.
Risk and Exploitability
The CVSS score is 9.8, indicating a critical severity. The EPSS score is less than 1 %, suggesting that the probability of exploitation discovered in the wild is presently very low, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw can be triggered remotely through a template input that an attacker controls. A successful exploit would grant full code execution on the host and can be accomplished without any special privileges or local access.
OpenCVE Enrichment