VYPR
Critical severity9.8OSV Advisory· Published Jun 26, 2026· Updated Jun 26, 2026

CVE-2026-0685

CVE-2026-0685

Description

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

Affected products

2
  • Firestats/Genshillm-create2 versions
    =0.7.9+ 1 more
    • (no CPE)range: =0.7.9
    • (no CPE)range: 0.7.9, 0.7.8, 0.7.7, …

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.