CriticalCritical vulnerability
CVE-2026-108598 (CVSS 9.3)
NVD · officialPublished Oct 10, 2026Risk 50/100
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.
Technical details
CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source