Description
A flaw was found in the `release-service-utils` component. This vulnerability, known as Server-Side Template Injection, allows an attacker to execute unauthorized code. By manipulating specific input fields, a malicious tenant can inject harmful commands into templates that are processed twice. This bypasses security measures, enabling the attacker to run arbitrary code within the `release-service-utils` system and potentially gain access to sensitive credentials.
Published: n/a
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The release-service-utils component contains a Server‑Side Template Injection flaw that allows a malicious tenant to inject code into templates processed twice by a non‑sandboxed Jinja renderer. By manipulating specific input fields, an attacker can cause arbitrary code execution within the release‑service‑utils environment and potentially read stored credentials.

Affected Systems

All deployments that include the release‑service‑utils component are affected. Vendor, product, and version details were not provided, so the scope is limited to installations that use this component regardless of other system components.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability. EPSS data is unavailable and the vulnerability is not listed in CISA KEV. The likely attack vector involves a malicious tenant who can submit data to the vulnerable input fields; successful exploitation would grant the attacker non‑privileged code execution within the component’s environment and the ability to read credentials stored therein.

Generated by OpenCVE AI on September 18, 2026 at 07:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade release‑service‑utils to a version that removes or sandbox the double‑pass Jinja rendering.
  • Configure the Jinja template engine to enforce a sandbox or disable template rendering entirely for untrusted data.
  • Validate and sanitize all user‑supplied template content before it reaches the render engine.

Generated by OpenCVE AI on September 18, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the `release-service-utils` component. This vulnerability, known as Server-Side Template Injection, allows an attacker to execute unauthorized code. By manipulating specific input fields, a malicious tenant can inject harmful commands into templates that are processed twice. This bypasses security measures, enabling the attacker to run arbitrary code within the `release-service-utils` system and potentially gain access to sensitive credentials.
Title release-service-utils: Server-Side Template Injection via two-pass non-sandboxed Jinja render
Weaknesses CWE-94
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-92218 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')