Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/edgewall/genshi/ |
|
History
Fri, 26 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Fri, 26 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Fri, 26 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions. | |
| Title | Server side template inject (SSTI) in Edgewall Genshi Template Engine | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published: 2026-06-26T15:45:11.283Z
Updated: 2026-06-26T17:36:14.375Z
Reserved: 2026-01-07T19:12:01.099Z
Link: CVE-2026-0685
Updated: 2026-06-26T15:50:40.957Z
No data.
No data.