V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-25526
ANC
CriticalConfirmedExploit available

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8…

CVSS
9.8
Critical
EPSS
0.01
p54
Published
2026-01-01
Updated
2026-01-01
Description

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.

Tags · CWE
Pre-auth
CWE-1336
Affected products
Jinjava < 2.7.6Jinjava 2.8.0–2.8.3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.009 · p54
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2026-25526
github-poc · https://github.com/av4nth1ka/jinjava-cve-2026-25526-poc
Enterprise
Affected products
ProductVendorStatus
Tracked
jinjava*Tracked