Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0685

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 9.8

Описание

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

A flaw was found in the Genshi Template Engine. This server-side template injection (SSTI) vulnerability in the expression evaluation component allows a remote attacker to achieve remote code execution (RCE). By sending crafted template expressions, an attacker can execute arbitrary code on the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6python-genshiNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-917
https://bugzilla.redhat.com/show_bug.cgi?id=2493606genshi: Genshi Template Engine: Remote Code Execution via Server-Side Template Injection

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 месяцев назад

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

CVSS3: 9.8
nvd
около 2 месяцев назад

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

CVSS3: 9.8
github
около 2 месяцев назад

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

9.8 Critical

CVSS3