CVE-2024-37301 - CVE House
Back to Database
Status published High CVE-2024-37301

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

Vulnerability Description

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37301

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

document-merge-service
Vulnerable Versions:
< 6.5.2

Timeline

Official Publish: June 11th, 2024
Last Modified: February 4th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.