CVE-2026-25526

CRITICAL

JinJava 2.7.0-2.7.5 and 2.8.0-2.8.2 - Remote Code Execution via ForTag Sandbox Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-25526. PoCs published by XiaomingX, av4nth1ka.

AI-analyzed exploit summary The repository contains only a minimal README with no exploit code, technical details, or lab setup instructions. It appears to be a placeholder for a PoC that has not been populated.

Description

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.

Exploits (2)

github STUB 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-25526

The repository contains only a minimal README with no exploit code, technical details, or lab setup instructions. It appears to be a placeholder for a PoC that has not been populated.

Classification
Stub 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by av4nth1ka · poc
https://github.com/av4nth1ka/jinjava-cve-2026-25526-poc

This repository contains a functional proof-of-concept exploit for CVE-2026-25526, targeting Jinjava. The exploit demonstrates file content reading, directory listing, and information disclosure via template injection, leveraging Java object manipulation to bypass sandbox restrictions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Jinjava (versions prior to 2.8.3)
No auth needed
Prerequisites: Access to a Jinjava template rendering endpoint · Legacy overrides enabled in Jinjava configuration
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0005
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1336
Status published
Products (2)
com.hubspot.jinjava/jinjava 2.8.0 - 2.8.3Maven
hubspot/jinjava < 2.7.6
Published Feb 04, 2026
Tracked Since Feb 18, 2026