CVE-2024-37301

HIGH

Pypi Document-merge-service < 6.5.2 - Remote Code Execution

Title source: rule
STIX 2.1

Description

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.

Scores

CVSS v3 7.2
EPSS 0.0560
EPSS Percentile 90.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-1336
Status published
Products (2)
adfinis/document-merge-service < 6.5.2
pypi/document-merge-service 0 - 6.5.2PyPI
Published Jun 11, 2024
Tracked Since Feb 18, 2026