CVE-2025-12107
Last modified
CVE-2025-12107 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Identity Server | 5.11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-12107?
How severe is CVE-2025-12107?
How do I fix CVE-2025-12107?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12100Incorrect Default Permissions vulnerability in MongoDB BI Co…8.8
- CVE-2025-12101Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Ga…5.9
- CVE-2025-12103A flaw was found in Red Hat Openshift AI Service. The Trusty…5
- CVE-2025-12104Outdated and Vulnerable UI Dependencies might potentially le…9.8
- CVE-2025-12105A flaw was found in the asynchronous message queue handling …7.5
- CVE-2025-12106Insufficient argument validation in OpenVPN 2.7_alpha1 throu…9.1
- CVE-2025-12108The Survision LPR Camera system does not enforce password pr…9.3
- CVE-2025-12109The Header Footer Script Adder – Insert Code in Header, Body…6.4
- CVE-2025-1211Versions of the package hackney before 1.21.0 are vulnerable…6.5
- CVE-2025-12110A flaw was found in Keycloak. An offline session continues t…5.4
- CVE-2025-12112The Insert Headers and Footers Code – HT Script plugin for W…6.4
- CVE-2025-12113The Alt Text Generator AI – Auto Generate & Bulk Update Alt …4.3
Are you affected by CVE-2025-12107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
