Template Processing Vulnerability in OpenBoxes by OpenBoxes
CVE-2026-19929
Key Information:
Badges
What is CVE-2026-19929?
A vulnerability has been discovered in OpenBoxes versions up to 0.9.6, specifically affecting the 'buildZebraTemplate' function within the file 'grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy'. This flaw allows improper neutralization of special elements used in the template processing engine, creating potential for remote exploitation. Attackers may leverage this vulnerability to manipulate templates maliciously. To mitigate the risk associated with this exposure, it is strongly recommended to upgrade to version 0.9.8 or 0.9.8-hotfix1. Additional information regarding the patch can be found at the related GitHub commit.
Affected Version(s)
OpenBoxes 0.9.0
OpenBoxes 0.9.1
OpenBoxes 0.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
