Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection High
CVE-2024-37301 was published for document-merge-service (pip) Jun 11, 2024
c0rydoras Credited to c0rydoras
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) High
CVE-2026-53964 was published for document-merge-service (pip) Aug 19, 2026
sofianeelhor Credited to sofianeelhor, c0rydoras, and tonghuaroot c0rydoras c0rydoras
tonghuaroot tonghuaroot
ProTip! Advisories are also available from the GraphQL API