document-merge-service vulnerabilities
CVEs whose affected-version data names the document-merge-service package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53964High· 7.2Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
▾ Twilightdocument-merge-service · document-merge-servicevia OSV
CVE-2024-37301High· 7.2document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
▾ Twilightdocument-merge-service · document-merge-serviceEPSS 1.0%via OSV