A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
References
| Link | Resource |
|---|---|
| https://github.com/AT190510-Cuong/CVE-2025-64087-SSTI- | Broken Link |
| https://github.com/opensagres/xdocreport | Product |
| https://github.com/opensagres/xdocreport/pull/705 | Issue Tracking Third Party Advisory |
| https://hackmd.io/@cuongnh/BJEnw7SAlg | Permissions Required |
| https://hackmd.io/@cuongnh/SkQvhEf0lx | Permissions Required |
Configurations
History
03 Feb 2026, 21:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:opensagres:xdocreport:*:*:*:*:*:*:*:* | |
| References | () https://github.com/AT190510-Cuong/CVE-2025-64087-SSTI- - Broken Link | |
| References | () https://github.com/opensagres/xdocreport - Product | |
| References | () https://github.com/opensagres/xdocreport/pull/705 - Issue Tracking, Third Party Advisory | |
| References | () https://hackmd.io/@cuongnh/BJEnw7SAlg - Permissions Required | |
| References | () https://hackmd.io/@cuongnh/SkQvhEf0lx - Permissions Required | |
| First Time |
Opensagres
Opensagres xdocreport |
Information
Published : 2026-01-20 16:16
Updated : 2026-02-03 21:49
NVD link : CVE-2025-64087
Mitre link : CVE-2025-64087
CVE.ORG link : CVE-2025-64087
JSON object : View
Products Affected
opensagres
- xdocreport
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
