← Back to browse · API

CVE-2025-70830

Severity
CRITICAL
CVSS
9.9
EPSS
0.01002
Risk score
39.95
CISA KEV
No
PoC
No
Published
2026-02-17
Modified
2026-02-17
First seen
2026-08-07
Aliases
EUVD-2025-207687, GHSA-XQ7W-6F6F-MH93
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-207687

Description

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

References