{"advisories":[{"id":"GHSA-gjx9-j8f8-7j74","source":"ghsa","title":"JinJava Bypass through ForTag leads to Arbitrary Java Execution","url":"https://github.com/advisories/GHSA-gjx9-j8f8-7j74"}],"cve":"CVE-2026-25526","enrichment":{"analysis":{"en":{"generated_at":"2026-04-17T23:11:04.952420+00:00","value":{"mitigation_remediation":["Upgrade JinJava to version 2.7.6 or 2.8.3 to apply the official fix. ","If an upgrade is infeasible, disable or remove the ForTag feature in the configuration to block the exploit path. ","Restrict template rendering to trusted users only and audit any input that feeds into templates to ensure no malicious ForTag expressions can be injected."],"summary":{"action":"Patch","impact":"Arbitrary Java execution via template injection"},"threat_synthesis":{"affected_systems":"The affected product is HubSpot's JinJava template engine. All releases of JinJava older than version 2.7.6 and older than 2.8.3 are vulnerable. Administrators using these versions should verify the installed version and plan an upgrade to a patched release.","description_and_impact":"JinJava, a Java-based template engine that emulates Django template syntax, is vulnerable to arbitrary Java execution in versions before 2.7.6 and 2.8.3. An attacker can inject malicious code through a ForTag bypass, allowing the instantiation of arbitrary Java classes and access to files, thus violating the sandboxing restrictions designed to contain template execution. This flaw corresponds to CWE‑1336 and enables attackers to run code with the privileges of the Java process that renders the template.","risk_and_exploitability":"The CVSS score of 9.8 categorizes the vulnerability as critical, indicating a high risk to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a low probability of exploitation in the short term, but the flaw is not listed in CISA's KEV catalog, meaning no known active exploitation campaigns are reported yet. Likely attack vectors involve an attacker who can influence the content of a template—such as a user-supplied template or a template stored in a database—to inject ForTag expressions that trigger arbitrary code execution. This inference is based on the description of the vulnerability, as the original data does not detail the exact exploitation method."}}}},"created":"2026-02-05T11:39:16.948610+00:00","updated":"2026-04-17T23:15:30.807374+00:00","vendors":["hubspot","hubspot$PRODUCT$jinjava"]},"epss":{"score":0.00917},"mitre":{"cpes":[],"created":"2026-02-04T21:26:58.572000+00:00","description":"JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/25xxx/CVE-2026-25526.json","references":["https://github.com/HubSpot/jinjava/commit/3d02e504d8bbb13bf3fe019e9ca7b51dfce7a998","https://github.com/HubSpot/jinjava/commit/c7328dce6030ac718f88974196035edafef24441","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.7.6","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.8.3","https://github.com/HubSpot/jinjava/security/advisories/GHSA-gjx9-j8f8-7j74"],"title":"JinJava Bypass through ForTag leads to Arbitrary Java Execution","updated":"2026-02-05T21:01:00.454000+00:00","vendors":[],"weaknesses":["CWE-1336"]},"nvd":{"cpes":["cpe:2.3:a:hubspot:jinjava:*:*:*:*:*:*:*:*"],"created":"2026-02-04T22:15:59.510000+00:00","description":"JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-25526.json","references":["https://github.com/HubSpot/jinjava/commit/3d02e504d8bbb13bf3fe019e9ca7b51dfce7a998","https://github.com/HubSpot/jinjava/commit/c7328dce6030ac718f88974196035edafef24441","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.7.6","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.8.3","https://github.com/HubSpot/jinjava/security/advisories/GHSA-gjx9-j8f8-7j74"],"title":null,"updated":"2026-06-17T10:24:47.677000+00:00","vendors":["hubspot","hubspot$PRODUCT$jinjava"],"weaknesses":["CWE-1336"]},"opencve":{"changes":[{"created":"2026-02-04T21:45:00+00:00","data":[{"details":{"new":"JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.","old":null},"type":"description"},{"details":{"new":"JinJava Bypass through ForTag leads to Arbitrary Java Execution","old":null},"type":"title"},{"details":{"added":["CWE-1336"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/HubSpot/jinjava/commit/3d02e504d8bbb13bf3fe019e9ca7b51dfce7a998","https://github.com/HubSpot/jinjava/commit/c7328dce6030ac718f88974196035edafef24441","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.7.6","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.8.3","https://github.com/HubSpot/jinjava/security/advisories/GHSA-gjx9-j8f8-7j74"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"57bb3f5a-da9c-4be4-b419-7b5ab96e173f"},{"created":"2026-02-05T11:45:00+00:00","data":[{"details":["hubspot","hubspot$PRODUCT$jinjava"],"type":"first_time"},{"details":{"added":["hubspot","hubspot$PRODUCT$jinjava"],"removed":[]},"type":"vendors"}],"id":"f21a17e9-98da-402c-8e8b-b7d124ee1ca2"},{"created":"2026-02-05T21:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ea6bb454-fe83-47a4-95b5-84a72c5714a2"},{"created":"2026-02-20T21:15:00+00:00","data":[{"details":{"added":["cpe:2.3:a:hubspot:jinjava:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"13477e22-a2ae-41dd-8379-2ef9b3899934"}],"cpes":{"data":["cpe:2.3:a:hubspot:jinjava:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2026-02-04T21:26:58.572000+00:00","provider":"mitre"},"description":{"data":"JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00917},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/HubSpot/jinjava/commit/3d02e504d8bbb13bf3fe019e9ca7b51dfce7a998","https://github.com/HubSpot/jinjava/commit/c7328dce6030ac718f88974196035edafef24441","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.7.6","https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.8.3","https://github.com/HubSpot/jinjava/security/advisories/GHSA-gjx9-j8f8-7j74"],"providers":["mitre","nvd"]},"title":{"data":"JinJava Bypass through ForTag leads to Arbitrary Java Execution","provider":"mitre"},"updated":{"data":"2026-04-17T23:15:30.807374+00:00","provider":"enrichment"},"vendors":{"data":["hubspot","hubspot$PRODUCT$jinjava"],"providers":["nvd","enrichment"]},"weaknesses":{"data":["CWE-1336"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-02-04T21:26:58.572000+00:00","description":"JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"JinJava Bypass through ForTag leads to Arbitrary Java Execution","updated":"2026-02-05T21:00:55.395000+00:00","vendors":[],"vulnrichment_repo_path":"2026/25xxx/CVE-2026-25526.json","weaknesses":[]}}