CVE-2026-108570: Furion .NET Framework View ViewEngine.cs RunCompile special elements in template engine
A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argument content results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Furion .NET Framework deployments up to version 4.9.9.95 are affected when using the View Engine component and its RunCompile functionality in framework/Furion/ViewEngine/Engines/ViewEngine.cs.
What access does an attacker need?
The issue can be exploited remotely with low attack complexity, but the stated vector requires low privileges. No user interaction is required.
Is public exploit information available?
Yes. An exploit has been publicly released and may be used in attacks.
What can be done if an update is not immediately available?
The available information does not identify a vendor fix or workaround. Reduce exposure by limiting access to functionality that accepts or compiles attacker-controlled template content and restricting low-privileged access to affected application features.