Pebbletemplates maintains a focused template-engine library that, despite its narrow product scope, is embedded in applications requiring dynamic content rendering and may be exposed through server-side template-injection attack surfaces. The recurring vulnerability pattern centers on file-path traversal, authorization checks, and access-control boundaries, reflecting the inherent risks of template processing and file-system interaction in the product's core functionality. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pebbletemplates over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37767CRITICAL Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the | Sep 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-19899CRITICAL Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public st | Dec 19, 2019 | 9.8 | 28 | NO | NO |
CVE-2025-1686MEDIUM Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker ca | Feb 27, 2025 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pebbletemplates.
Media articles that mention a CVE ID that affects a product developed by Pebbletemplates — matched by CVE ID, not by vendor name.