document-merge-service
Merge Document Template Service
Activity
- Latest release
- 7mo ago
- Total releases
- 32
- Cadence
- ~12 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Jan 12, 2023
| Version | Released | |
|---|---|---|
9.0.0
major
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
9.0.0
major
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
8.1.0
minor
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.1.0
minor
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
8.0.3
patch
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.0.3
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
8.0.2
patch
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.0.2
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
8.0.0
major
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.0.0
major
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
7.1.0
minor
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.1.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
7.0.2
patch
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.2
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
7.0.1
patch
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
7.0.0
major
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.0
major
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
6.6.1
patch
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.6.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
6.6.0
minor
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.6.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
6.4.6
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.6
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.5.2
patch
1 CVE
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.5.2
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
6.5.1
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.5.1
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
6.5.0
minor
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.5.0
minor
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.4.5
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.5
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.4.4
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.4
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.4.3
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.3
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.4.2
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.2
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.4.1
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.4.0
minor
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.4.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.3.1
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.3.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.3.0
minor
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.3.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.2.2
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.2.2
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.2.1
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.2.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.2.0
minor
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.2.0
minor
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
6.1.2
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.1.2
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.1.1
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.1.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.1.0
minor
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.1.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
6.0.0
major
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.0.0
major
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
5.2.1
patch
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.2.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
5.2.0
initial
2 CVEs
CVE-2026-53964
PYSEC-2026-3830
GHSA-w47q-945m-q9pc
Sep 10, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactA remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the PatchesIt has been patched in v9.1.0 WorkaroundsDisable the upload/usage of XLSX templates. ReferencesAre there any links users can visit to find out more? https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 20 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.0.0
7.0.1
7.0.2
7.1.0
8.0.0
8.0.2
8.0.3
8.1.0
9.0.0
Fixed in
9.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-37301
PYSEC-2026-1314
GHSA-v5gf-r78h-55q6
Jul 07, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted? A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. PatchesHas the problem been patched? What versions should users upgrade to? It has been patched in v6.5.2 ReferencesAre there any links users can visit to find out more?
POCAdd the following to a document, upload and render it:
The index might be different, so to debug this first render a template with Affected versions
5.2.0
5.2.1
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
+ 8 more Show less
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
Fixed in
6.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.2.0
initial
Dependencies (18)
+ 10 more
Changelog
|