CVE-2025-70830

Critical severity, CVSS 9.9. EPSS: 1% chance of exploitation in the next 30 days.

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

Published 2026-02-17. Last modified 2026-06-17.