CVE-2025-60355

CRITICAL LAB

zhangyd-c OneBlog <2.3.9 - Server-Side Template Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-60355. PoCs published by exploitintel.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-60355, a critical Server-Side Template Injection (SSTI) vulnerability in OneBlog. The exploit leverages FreeMarker's unsafe class resolution to achieve remote code execution via crafted template injection.

Description

zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

Exploits (1)

github WORKING POC
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2025-60355

This repository contains a functional exploit for CVE-2025-60355, a critical Server-Side Template Injection (SSTI) vulnerability in OneBlog. The exploit leverages FreeMarker's unsafe class resolution to achieve remote code execution via crafted template injection.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OneBlog (up to and including version 2.3.9)
Auth required
Prerequisites: Authenticated admin access to inject payload · Unauthenticated access to trigger payload via public endpoints
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/line2222/vuln/issues/4

Related Analysis

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 33.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Lab Environment

EIP LAB Lab screenshot
admin docker pull ghcr.io/exploitintel/cve-2025-60355-admin:latest
builder docker pull ghcr.io/exploitintel/cve-2025-60355-builder:latest
mysql docker pull ghcr.io/exploitintel/cve-2025-60355-mysql:latest
web docker pull ghcr.io/exploitintel/cve-2025-60355-web:latest

Details

CWE
CWE-1336
Status published
Products (1)
zhyd/oneblog < 2.3.9
Published Oct 28, 2025
Tracked Since Feb 18, 2026