Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r8w2-w357-9pjv | XDocReport affected by a Server-Side Template Injection (SSTI) vulnerability |
Tue, 03 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:opensagres:xdocreport:*:*:*:*:*:*:*:* |
Wed, 21 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1336 | |
| Metrics |
cvssV3_1
|
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensagres
Opensagres xdocreport |
|
| Vendors & Products |
Opensagres
Opensagres xdocreport |
Tue, 20 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-21T14:34:26.011Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64087
Updated: 2026-01-21T14:34:21.559Z
Status : Analyzed
Published: 2026-01-20T16:16:06.070
Modified: 2026-02-03T21:49:59.897
Link: CVE-2025-64087
No data.
OpenCVE Enrichment
Updated: 2026-01-21T11:20:05Z
Github GHSA