{"id":"CVE-2026-31020","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-31020","summary":"In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders…","details":"In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulnerability that can be exploited to achieve full remote code execution (RCE).","published":"2026-09-04T17:16:56.910","modified":"2026-09-04T17:16:56.910","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://arc53.com"},{"type":"WEB","url":"https://github.com/PhDg1410/CVE/tree/main/CVE-2026-31020"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T17:16:56.910"}}