CVE-2025-70830

Publication date

2026-02-17 00:00:00

Family

mitre

State

PUBLISHED

Description

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.