Improper Neutralization of Special Elements Used in a Template Engine Affecting org.xwiki.commons:xwiki-commons-velocity package, versions [,17.6.0-rc-1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.29% (53rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGXWIKICOMMONS-12194802
  • published26 Aug 2025
  • disclosed20 Aug 2025
  • creditmalcxlmj

Introduced: 20 Aug 2025

NewCVE-2025-51991  (opens in a new tab)
CWE-1336  (opens in a new tab)

How to fix?

Upgrade org.xwiki.commons:xwiki-commons-velocity to version 17.6.0-rc-1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine via improper handling of dynamic template rendering in the HTTP Meta Info field of the Global Preferences Presentation section. An attacker can execute arbitrary template logic on the server by injecting crafted Apache Velocity template code. This may expose internal server information or, depending on configuration, allow further exploitation such as remote code execution or sensitive data leakage.

Note:

This is only exploitable if the attacker has authenticated administrator access to the Administration interface.

References

CVSS Base Scores

version 4.0
version 3.1