VYPR
Unrated severityNVD Advisory· Published Feb 19, 2026· Updated Mar 6, 2026

Potential authenticated Server-Side Template Injection (SSTI) vulnerability.

CVE-2025-12107

Description

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates.

Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.

Affected products

1
  • WSO2/WSO2 Identity Serverv5
    Range: 5.11.0.130

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.