Critical severity9.8OSV Advisory· Published Jan 20, 2026· Updated Jun 17, 2026
CVE-2025-64087
CVE-2025-64087
Description
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarkerMaven | < 2.2.0 | 2.2.0 |
Affected products
3xdocreport-parent-1.0.5, xdocreport-parent-1.0.6, xdocreport-parent-2.0.0, …+ 1 more
- (no CPE)range: xdocreport-parent-1.0.5, xdocreport-parent-1.0.6, xdocreport-parent-2.0.0, …
- cpe:2.3:a:opensagres:xdocreport:*:*:*:*:*:*:*:*range: >=1.0.0,<=2.1.0
- ghsa-coordsRange: < 2.2.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-r8w2-w357-9pjvghsaADVISORY
- github.com/opensagres/xdocreport/pull/705nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-64087ghsaADVISORY
- github.com/opensagres/xdocreport/commit/3b35d105e5ae2006bcaa2b07563188efc466711dghsaWEB
- hackmd.io/@cuongnh/BJEnw7SAlgnvdPermissions RequiredWEB
- hackmd.io/@cuongnh/SkQvhEf0lxnvdPermissions RequiredWEB
News mentions
0No linked articles in our index yet.