VYPR

floci

by Floci Io

CVEs (1)

  • CVE-2026-108598CriOct 10, 2026
    risk 0.57cvss 9.8epss —

    Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util…