CVE-2026-108598: Floci-Io Floci
Critical severity, CVSS 9.8.
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.
Affected products
- Floci-Io Floci: from 1.1.0, before 2.2.0 (fixed in 2.2.0)
Published 2026-10-10. Last modified 2026-10-10.