Vulnerability  ·  2026-10-11

Floci AI gateway: unauthenticated Velocity template injection → remote OS command execution in the JVM (CVSS 9.3)

VulnerabilityHigh impactGlobalCVE-2026-108598
Discovered via open-web sweep (not in the supplied NVD seed): NVD REST API confirms publication 2026-10-10, CVSS 9.8 v3.1 / 9.3 v4.0, with a public PoC referenced in the advisory (exploitarium). Unauthenticated attackers execute commands by crafting a Velocity mapping template in a MOCK API integration.
Template-injection-to-RCE in an AI platform's API-gateway engine is a full unauthenticated compromise primitive in the LLM/tool integration layer — an attacker lands on whichever host runs Floci with the JVM's privileges.
VtlTemplateEngine runs attacker-supplied Velocity mapping templates with unrestricted reflection: a REST API with a MOCK integration uses a template that reaches Runtime/ProcessBuilder via $util reflection to execute OS commands in the Floci JVM, unauthenticated (CWE-94).
floci 1.1.0 <= v < 2.2.0 (VtlTemplateEngine)
Upgrade to 2.2.0 (commit 144b90e6fa861a5ac882e99a090d503da01945c4; GHSA-3p4c-wp7w-mgjx). Disable runtime reflection in template engine config and restrict MOCK-integration template authoring to trusted admins.
NVD CVE-2026-108598NVD REST APIGitHub advisory GHSA-3p4c-wp7w-mgjx
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →