CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-108598 — Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE...
·Source: NIST NVD
Updated:
Executive Summary
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.
Analysis
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM. CVSS Score: 9.8. Published: 2026-10-10T19:16:58.347.