Impact
The vulnerability is a server‑side template injection in the xltpl library used by the Document Merge Service. It allows an attacker to supply malicious code in an XLSX template uploaded through the merge API, which is executed in a Jinja environment running as the document‑merge‑server user with UID 901. The resulting code execution grants the attacker substantial control over the container, enabling further lateral movement or persistence.
Affected Systems
adfinis Document Merge Service versions prior to 9.1.0 are affected. All releases before 9.1.0 can be exploited when XLSX templates are processed.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and the vulnerability can be exploited remotely by uploading a crafted XLSX file to the exposed API. The EPSS score is not available, but the lack of a KEV listing suggests no known public exploits yet. Nonetheless, the capability for code execution makes it a high‑risk exposure that should be remediated promptly.
OpenCVE Enrichment
Github GHSA