Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9x82-rm84-c6x7 | DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN |
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0. | |
| Title | DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-02T18:03:01.091Z
Reserved: 2026-06-01T18:50:36.056Z
Link: CVE-2026-49832
No data.
Status : Received
Published: 2026-09-02T18:19:32.830
Modified: 2026-09-02T19:17:19.197
Link: CVE-2026-49832
No data.
OpenCVE Enrichment
No data.
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
Github GHSA