Improper Neutralization of Special Elements Used in a Template Engine Affecting document-merge-service package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-DOCUMENTMERGESERVICE-20158950
  • published27 Sept 2026
  • disclosed19 Aug 2026
  • creditUnknown

Introduced: 19 Aug 2026

CVE-2026-53964  (opens in a new tab)
CWE-1336  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

document-merge-service is a Merge Document Template Service

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in the processing of XLSX templates using a non-sandboxed Jinja environment. An attacker can execute arbitrary code on the server by supplying malicious template content. This is only exploitable if XLSX templates are enabled and processed by the service.

Workaround

This vulnerability can be mitigated by disabling the upload or usage of XLSX templates.

CVSS Base Scores

version 4.0
version 3.1