CVE-2025-70830

A

Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

Configurations

No configuration.

History

18 Feb 2026, 17:52

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Inyección de Plantillas del Lado del Servidor (SSTI) en el motor de plantillas Freemarker de Datart v1.0.0-rc.3 permite a atacantes autenticados ejecutar código arbitrario mediante la inyección de sintaxis de plantilla Freemarker manipulada en el campo de script SQL.

17 Feb 2026, 16:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 16:20

Updated : 2026-02-18 17:52


NVD link : CVE-2025-70830

Mitre link : CVE-2025-70830

CVE.ORG link : CVE-2025-70830


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')