CVE-2026-19929
LOW
2,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: low
MEDIUM
6,5
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: partial
Availability: partial
Description
AI Translation Available
A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 will fix this issue. The identifier of the patch is deeac6a4a7aba86ce99c4bda37142e41d209293e. It is recommended to upgrade the affected component.
791
Incomplete Filtering of Special Elements
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Unexpected State
Applicable Platforms
All platforms may be affected
1336
Improper Neutralization of Special Elements Used in a Template Engine
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
Java, PHP, Python, JavaScript, Interpreted
Technologies:
Not Technology-Specific, AI/ML, Client Server
https://gist.github.com/nedlir/220a30213b5a5c6bc26d1000012c6a4d
https://github.com/OpenBoxes/OpenBoxes/
https://github.com/openboxes/openboxes/commit/deeac6a4a7aba86ce99c4bda37142e41d…
https://github.com/OpenBoxes/OpenBoxes/pull/5943
https://github.com/openboxes/openboxes/releases/tag/v0.9.8
https://github.com/OpenBoxes/OpenBoxes/security/advisories/GHSA-8wxj-vghp-jpcq
https://vuldb.com/cve/CVE-2026-19929
https://vuldb.com/submit/872054
https://vuldb.com/vuln/390180
https://vuldb.com/vuln/390180/cti