CVE-2026-71880: Gbif Integrated Publishing Toolkit

High severity, CVSS 7.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection

Affected products

  • Gbif Integrated Publishing Toolkit: before 3.3.4 (fixed in 3.3.4)

Published 2026-08-18. Last modified 2026-08-31.