PYSEC-2026-3830

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/document-merge-service/PYSEC-2026-3830.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3830
Aliases
Published
2026-09-10T09:44:51Z
Modified
2026-09-10T12:15:05Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Details

Impact

A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template.

Patches

It has been patched in v9.1.0

Workarounds

Disable the upload/usage of XLSX templates.

References

Are there any links users can visit to find out more?

https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti

References

Affected packages

PyPI / document-merge-service

Package

Name
document-merge-service
View open source insights on deps.dev
Purl
pkg:pypi/document-merge-service

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.1.0

Affected versions

5.*
5.2.0
5.2.1
6.*
6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.4.1
6.4.2
6.4.3
6.4.4
6.4.5
6.4.6
6.5.0
6.5.1
6.5.2
6.6.0
6.6.1
7.*
7.0.0
7.0.1
7.0.2
7.1.0
8.*
8.0.0
8.0.2
8.0.3
8.1.0
9.*
9.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/document-merge-service/PYSEC-2026-3830.yaml"