File Inclusion Vulnerability in Pebble Templates by PebbleTemplates
CVE-2025-1686
What is CVE-2025-1686?
The package io.pebbletemplates:pebble is subject to a vulnerability that allows high-privileged attackers to exploit the 'include' tag. By creating specific malicious notification templates, attackers can gain unauthorized access to sensitive local files, such as /etc/passwd or /proc/1/environ. This poses a significant risk as attackers can leverage this flaw to manipulate file inclusions in a way that can expose confidential information. To mitigate this issue, it is recommended to disable the include macro in Pebble Templates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
io.pebbletemplates:pebble 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
