CVE-2026-0685: Server side template inject (SSTI) in Edgewall Genshi Template Engine
Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Edgewall Genshi Template Engineto a version that resolves this vulnerability.Fixed in 0.7.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0685?
CVE-2026-0685 has a risk score of 92, indicating a critical severity level.
How do I fix CVE-2026-0685?
To mitigate CVE-2026-0685, upgrade to a patched version of the Edgewall Genshi Template Engine that addresses the vulnerability.
What kind of vulnerability is CVE-2026-0685?
CVE-2026-0685 is a Server-Side Template Injection (SSTI) vulnerability allowing remote code execution.
What versions of Edgewall Genshi Template Engine are affected by CVE-2026-0685?
CVE-2026-0685 affects Genshi Template Engine version 0.7.9.
Could CVE-2026-0685 lead to remote code execution?
Yes, CVE-2026-0685 allows an attacker to achieve remote code execution through crafted template expressions.