<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:floci:floci:1.1.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aflocifloci1.1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 19:55:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aflocifloci1.1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Floci VtlTemplateEngine</title><link>https://feed.craftedsignal.io/briefs/2026-10-floci-rce/</link><pubDate>Sat, 10 Oct 2026 19:55:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-floci-rce/</guid><description>An unauthenticated remote code execution vulnerability in Floci 1.1.0-2.1.9 allows attackers to achieve command execution via malicious Velocity templates.</description><content:encoded><![CDATA[<p>Floci versions 1.1.0 through 2.1.9 are susceptible to a critical remote code execution vulnerability (CVE-2026-108598) located within the VtlTemplateEngine component. The vulnerability arises from unrestricted processing of Velocity mapping templates used in API integrations. An unauthenticated attacker can exploit this by creating a REST API endpoint configured with a MOCK integration. By injecting malicious Velocity syntax that utilizes '$util' reflection, the attacker can access dangerous Java classes such as 'Runtime' or 'ProcessBuilder'. This allows the execution of arbitrary OS commands with the privileges of the Floci Java Virtual Machine process. This flaw poses a high risk to organizational infrastructure, as it provides a trivial vector for initial access and full system compromise without requiring authentication.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies an internet-facing instance of Floci.</li>
<li>The attacker authenticates or interacts with the public API endpoint, specifically targeting the REST API integration management interface.</li>
<li>The attacker creates a new MOCK integration via the Floci REST API.</li>
<li>The attacker provides a custom Velocity template containing reflective payload syntax targeting 'java.lang.Runtime' or 'java.lang.ProcessBuilder'.</li>
<li>The Floci application saves and subsequently evaluates the malicious template within the VtlTemplateEngine.</li>
<li>The VtlTemplateEngine executes the reflected code within the JVM context.</li>
<li>The attacker achieves arbitrary command execution on the underlying host operating system.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary system commands, leading to complete compromise of the Floci application host. Potential outcomes include full data exfiltration, persistent unauthorized access, lateral movement within the network, and the deployment of additional malware or ransomware.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Upgrade all instances of Floci to version 2.2.0 or later to patch CVE-2026-108598.</li>
<li>If patching cannot be performed immediately, restrict network access to the Floci API management interface to trusted internal segments only.</li>
<li>Monitor webserver access logs for anomalous POST requests directed at API integration endpoints, specifically looking for Velocity template syntax or reflective Java keywords in request bodies.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>