CVE-2026-19929 | OpenBoxes up to 0.9.6 Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine (GHSA-8wxj-vghp-jpcq)

SecurityVulns

A vulnerability classified as critical has been found in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation leads to improper neutralization of special elements used in a template engine.

This vulnerability is traded as CVE-2026-19929. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More