fief-server
Users and authentication management SaaS
Activity
- Latest release
- 1y ago
- Total releases
- 121
- Cadence
- ~6 days
- Last 12 months
- 0
Details
- First release
- Feb 06, 2022
| Version | Released | |
|---|---|---|
0.30.0
minor
| ||
0.29.2
patch
| ||
0.29.1
patch
| ||
0.29.0
minor
| ||
0.28.9
patch
| ||
0.28.8
patch
| ||
0.28.7
patch
| ||
0.28.6
patch
| ||
0.28.5
patch
| ||
0.28.4
patch
| ||
0.28.3
patch
| ||
0.28.2
patch
| ||
0.28.1
patch
| ||
0.28.0.post1
pre
| ||
0.28.0
minor
| ||
0.27.0
minor
| ||
0.26.3
patch
| ||
0.26.2
patch
| ||
0.26.1
patch
| ||
0.26.0
minor
| ||
0.25.3
patch
| ||
0.25.2
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.25.1
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.25.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.9
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.8
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.7
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.6
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.5
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.4
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.3
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.2
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.1
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.24.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.23.2
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.23.1
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.23.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.22.2
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.22.1
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.21.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.20.1
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.20.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.19.2
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.19.1
patch
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.19.0
minor
1 CVE
GHSA-hj8m-9fhf-v7jp
Jun 23, 2023
fief-server Server-Side Template Injection vulnerability
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Server-Side Template InjectionOverview of the VulnerabilityServer-Side Template Injection (SSTI) is a vulnerability within application templating engines where user input is improperly handled and is embedded into the template, possibly leading code being executed. An attacker can use SSTI to execute code on the underlying system by manipulating values within the embedded template. When code is executed within the underlying system, it can allow an attacker to run permissioned commands under the exploited process, or exploit Cross-Site Scripting (XSS) to run code within the user's browser. Business ImpactSSTI can lead to reputational damage for the business due to a loss in confidence and trust by users. If an attacker successfully executes code within the underlying system, it can result in data theft and indirect financial losses. Steps to Reproduce
Payload:
Proof of Concept (PoC)The screenshot(s) below demonstrates the SSTI:
Affected versions
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.23.1
0.23.2
+ 13 more Show less
0.24.0
0.24.1
0.24.2
0.24.3
0.24.4
0.24.5
0.24.6
0.24.7
0.24.8
0.24.9
0.25.0
0.25.1
0.25.2
Fixed in
0.25.3
References Updated Sep 02, 2026 · Source: OSV.dev | ||
0.18.0
minor
| ||
0.17.4
patch
| ||
0.17.3
patch
| ||
0.17.2
patch
|
