CRITICAL
opensagres
CVE published 2026-08-17
CVE-2026-38165
A Server-Side Template Injection (SSTI) vulnerability in xdocreport versions 0.9.2 to 2.2.0 allows attackers to execute arbitrary code via a crafted expression. Defenders should assess exposure, prioritize remediation, and verify affected versions and vendor fixes. This vulnerability poses significant risks to applications using xdocreport, as attackers can leverage it to gain control over the server. Def [truncated]