Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-53964— Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Quick assessment

Affected
adfinis document-merge-service
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Document Merge Service 是一个文档模板合并服务,提供 API 用于管理模板并将给定数据与模板进行合并。在版本 9.1.0 之前,存在一个通过服务端模板注入(SSTI)导致的远程代码执行(RCE)漏洞,允许攻击者提供的代码在服务端上下文中以 document-merge-server 用户(UID 901)的身份执行,从而使攻击者能够对容器获得相当程度的控制。该漏洞仅限于 XLSX 模板,因为 xltpl 库在处理此类模板时使用了非沙箱化的 Jinja 环境。该问题已在版本 9.1.0 中修复。

CVSS 7.2 · High EPSS 0.49% · P40

Affected Version Matrix 1

VendorProduct Version RangeStatus
adfinis document-merge-service < 9.1.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53964

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Source: CVE Program / CVE List V5
Vulnerability Description
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template. This issue has been patched in version 9.1.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1336
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
adfinis document-merge-service < 9.1.0 -

II. Public POCs for CVE-2026-53964

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53964

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-53964 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53964

No comments yet


Leave a comment