CRITICAL
floci-io
CVE published 2026-10-10
CVE-2026-108598
CVE-2026-108598 is a critical vulnerability in Floci versions 1.1.0 before 2.2.0, allowing unauthenticated attackers to execute OS commands via unrestricted Velocity mapping templates in VtlTemplateEngine. This issue arises from the use of $util reflection to reach Runtime or ProcessBuilder, enabling command execution in the Floci JVM. The vulnerability has a CVSS score of 9.3 and is considered critical.