CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-108598 — Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE...

·Source: NIST NVD

Updated:

Executive Summary

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

Analysis

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM. CVSS Score: 9.8. Published: 2026-10-10T19:16:58.347.

Indicators of Compromise (1)

CVE (1)
CVE-2026-108598
Source Attribution

Originally published by NIST NVD on Oct 10, 2026. Verified by: NIST.

Related Threats