PatchSiren

floci-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL floci-io CVE published 2026-10-10

CVE-2026-108598

CVE-2026-108598 is a critical vulnerability in Floci versions 1.1.0 before 2.2.0, allowing unauthenticated attackers to execute OS commands via unrestricted Velocity mapping templates in VtlTemplateEngine. This issue arises from the use of $util reflection to reach Runtime or ProcessBuilder, enabling command execution in the Floci JVM. The vulnerability has a CVSS score of 9.3 and is considered critical.