PT-2026-25363 · Fit2Cloud+2 · Jumpserver
Sourbyte05
·
Published
2026-03-13
·
Updated
2026-03-13
·
CVE-2026-31864
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JumpServer (affected versions not specified)
Description
JumpServer is a bastion host and operation and maintenance security audit system. A Server-Side Template Injection (SSTI) issue exists in the Applet and VirtualApp upload functionality. This can be exploited by users with administrative privileges, specifically those with Application Applet Management or Virtual Application Management permissions. Successful exploitation allows attackers to execute arbitrary code within the JumpServer Core container. The root cause is the unsafe use of Jinja2 template rendering when processing user-uploaded YAML configuration files. When a user uploads an Applet or VirtualApp ZIP package, the manifest.yml file is processed through Jinja2 without sandbox restrictions, enabling template injection attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jumpserver