PT-2026-44501 · Unknown · Fossbilling
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.0
Description
A Server-Side Template Injection (SSTI) issue exists in the template rendering system. Administrators with access to features that render Twig templates—such as email templates, mass mail campaigns, custom payment adapters, and the
string render API endpoint—can inject arbitrary Twig expressions. This occurs because Twig templates are rendered without a sandbox, granting access to the full Twig environment, API context, and the application's dependency injection container, which can lead to information disclosure and remote code execution. Real-world exploitation has been observed in targeted campaigns.Recommendations
Update to version 0.8.0.
Audit existing email templates for suspicious Twig expressions.
Rotate all admin and client API tokens.
Block external access to the
/api/system/* endpoint at the reverse proxy or WAF.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fossbilling