CVE-2026-108598: Floci 1.1.0 before 2.2.0 RCE via API Gateway VTL Mapping Templates
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flocito a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Floci versions from 1.1.0 up to, but not including, 2.2.0 are affected when API Gateway VTL mapping templates can be used to create a REST API with a MOCK integration.
Does exploitation require credentials or user interaction?
No. The reported attack is unauthenticated and requires no user interaction; an attacker can use an unrestricted Velocity mapping template to reach Java Runtime or ProcessBuilder and execute operating-system commands in the Floci JVM.
What component or configuration enables the attack path?
The vulnerable path is VtlTemplateEngine processing unrestricted Velocity mapping templates. The described proof of concept uses a REST API configured with a MOCK integration and a template that uses $util reflection.