{"id":"CVE-2026-71880","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71880","summary":"Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and…","details":"Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection","published":"2026-08-18T18:19:33.097","modified":"2026-08-18T18:19:33.097","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/gbif/ipt/issues/3118"},{"type":"WEB","url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0016.md"},{"type":"WEB","url":"https://www.gbif.org/ipt"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T18:19:33.097"}}