Sceawere

Vulnerability Detail

CVE-2026-108598UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Floci VtlTemplateEngine Code Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
floci-io
Product
floci
Attack Type
Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T19:16:58.347Z",
  "pubdate": "2026-10-10T19:16:58.347Z",
  "executiveSummary": "Floci versions 1.1.0 through 2.1.x are susceptible to a critical code injection vulnerability located within the VtlTemplateEngine component. This vulnerability stems from an insecure implementation of Velocity mapping templates that permits the execution of arbitrary operating system commands.\nAn unauthenticated, remote attacker can leverage this flaw by creating a REST API endpoint utilizing a MOCK integration. By injecting a crafted payload into the template, an attacker can utilize Velocity's '$util' reflection capabilities to access sensitive Java classes, such as 'java.lang.Runtime' or 'java.lang.ProcessBuilder'.\nSuccessful exploitation results in Remote Code Execution (RCE) with the privileges of the Floci JVM process. Given the nature of this vulnerability, the impact includes full system compromise, data exfiltration, and potential lateral movement within the hosting infrastructure. The attack requires no authentication, making it highly attractive for exploitation against exposed Floci instances. Organizations should prioritize upgrading to version 2.2.0 or higher to address the underlying architectural flaw.",
  "technicalDetails": "The vulnerability resides in the VtlTemplateEngine, which is responsible for processing Velocity templates in Floci. The engine fails to adequately sandbox the template environment, allowing for unrestricted access to Java reflection and static methods. The root cause is the exposure of the '$util' context object within the Velocity template evaluation process.\nThe exploitation flow begins with the attacker accessing the Floci interface to define a new REST API endpoint. During the configuration of the API's MOCK integration, the attacker provides a malicious Velocity template string. When this endpoint is invoked, the VtlTemplateEngine renders the template using the attacker-supplied input.\nBecause the engine does not restrict access to reflection, an attacker can invoke 'java.lang.Runtime.getRuntime().exec()' or 'java.lang.ProcessBuilder' to interact with the underlying host operating system. A representative payload might leverage the following Velocity syntax: '$util.getClass().forName(\"java.lang.Runtime\").getMethod(\"getRuntime\",null).invoke(null,null).exec(\"COMMAND_HERE\")'.\nUpon execution, the Floci JVM interprets these instructions, effectively bypassing application-layer security controls. The attacker maintains control over the execution context, enabling the delivery of secondary payloads, the enumeration of the filesystem, or the establishment of persistent backdoors within the server environment. Since the template evaluation occurs server-side, the process executes with the effective permissions of the JVM process user. Consequently, if the service is running with elevated privileges, the attacker gains full control over the host system. This vulnerability does not require prior knowledge of the target's internal state or administrative credentials, as the vector is accessible through standard API configuration workflows."
}
CVE-2026-108598: Floci VtlTemplateEngine Code Injection (CRITICAL Severity, CVSS: 9.8) | Sceawere