Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
Vulnerability Description
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template references a user-controlled token (such as #ActingUserName# or #UserName#, populated from a member's display name), an authenticated member can set their display name to JSON metacharacters and inject arbitrary key-value pairs into the rendered payloads delivered to webhook, SIEM, Slack, Teams, or Datadog endpoints, making injected fields indistinguishable from legitimate template output.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
Bitwarden Server 输入验证错误漏洞
Vulnerability Description
Bitwarden server是美国Bitwarden公司开源的一款密码管理服务器软件。 Bitwarden Server 2026.4.0版本存在输入验证错误漏洞,该漏洞源于IntegrationTemplateProcessor.ReplaceTokens()函数在替换用户可控值到事件集成模板时未进行JSON编码,可能导致经过身份验证的成员注入任意键值对到渲染的有效载荷中。
CVSS Information
N/A
Vulnerability Type
N/A