CVE-2026-108598: Floci-Io Floci

Critical severity, CVSS 9.8.

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

Affected products

  • Floci-Io Floci: from 1.1.0, before 2.2.0 (fixed in 2.2.0)

Published 2026-10-10. Last modified 2026-10-10.