Sceawere

Vulnerability Detail

CVE-2026-108570UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Furion ViewEngine Template Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
4h ago
Vendor
Furion
Product
.NET Framework
Attack Type
Improper Neutralization of Special Elements Used in a Template Engine
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argument content results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-11T11:16:59.980Z",
  "pubdate": "2026-10-11T11:16:59.980Z",
  "executiveSummary": "A critical Server-Side Template Injection (SSTI) vulnerability exists in the Furion .NET Framework, specifically affecting the View Engine component.\nThe vulnerability resides in the RunCompile function within the ViewEngine.cs file, where improper neutralization of user-supplied input allows for the injection of arbitrary code into the template processing engine.\nThe flaw affects all versions of Furion .NET Framework up to and including 4.9.9.95.\nThe vulnerability is exploitable remotely without requiring authentication, granting an attacker the ability to achieve remote code execution (RCE) on the underlying host.\nGiven that public exploit code exists, the risk is severe, potentially leading to total system compromise, unauthorized data access, and persistent backend manipulation.\nAs the vendor has remained unresponsive to disclosure efforts, no official patch is currently available, necessitating immediate manual defensive intervention by system administrators.",
  "technicalDetails": "The vulnerability is rooted in the insecure handling of the 'content' argument passed to the RunCompile function located in 'framework/Furion/ViewEngine/Engines/ViewEngine.cs'. The View Engine performs dynamic compilation of template strings; however, it fails to sanitize or validate user-provided input before incorporating it into the compilation process.\nAttackers can leverage this improper neutralization to inject malicious Razor or C# syntax into the template engine. When the RunCompile function processes the manipulated content, the underlying .NET Roslyn compiler or the specific View Engine implementation treats the injected malicious payload as legitimate executable code.\nThe attack flow begins when an attacker submits a crafted payload containing template directives or malicious C# expressions via an input vector that reaches the vulnerable RunCompile function. The engine parses this input, fails to enforce security boundaries, and proceeds to compile the template. Consequently, the injected payload executes within the context of the application's process.\nBecause the component is designed to handle dynamic template compilation, the execution context typically inherits the permissions of the application pool or the identity running the .NET service. This effectively grants the attacker the ability to invoke system commands, interact with the file system, or exfiltrate sensitive configuration data, including database connection strings and environment variables.\nExploitation is remote, does not require a prior authentication session, and can be triggered by any entry point that passes uncontrolled input to the ViewEngine's compilation logic. This makes the flaw highly susceptible to automated scanning and opportunistic exploitation by threat actors using public exploit proof-of-concepts.\nThe impact post-exploitation is critical, as it bypasses standard application-level access controls. Once RCE is achieved, the attacker can establish a reverse shell, deploy backdoors for persistent access, or pivot within the internal network. The lack of input sanitization within the engine's core compilation logic represents a fundamental failure in the application's security architecture regarding input handling in dynamic code generation."
}
CVE-2026-108570: Furion ViewEngine Template Injection (MEDIUM Severity, CVSS: 6.3) | Sceawere