CVE-2026-53964
Received Received - Intake

Remote Code Execution in Document Merge Service via SSTI

Vulnerability report for CVE-2026-53964, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template. This issue has been patched in version 9.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
adfinis document-merge-service to 9.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a remote code execution (RCE) flaw in the Document Merge Service. It occurs via server-side template injection (SSTI) when processing XLSX templates. Attackers can execute arbitrary code on the server with the privileges of the document-merge-server user (UID 901), gaining significant control over the container.

Detection Guidance

Check if your document-merge-service version is below 9.1.0. Inspect XLSX template processing logs for unusual Jinja template syntax or unexpected code execution traces. Monitor for unauthorized processes running as the document-merge-server user (UID 901).

Impact Analysis

An attacker exploiting this vulnerability could gain control over the server, potentially accessing sensitive data, modifying system configurations, or disrupting services. The impact includes compromised confidentiality, integrity, and availability of the system.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance with these regulations.

Mitigation Strategies

Upgrade document-merge-service to version 9.1.0 or later. Disable XLSX template uploads or usage as a temporary workaround. Restrict access to the service to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53964. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart