How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Security Release for issue #5160 and #14869

calendar_today July 3, 2026 person ced domain tryton

The user titou has discovered that the administrator group can execute Python code on the server which is hidden inside an uploaded report template . And Dan Shallom has discovered that the same can also be accomplished by the marketing group when uploading marketing email templates . Impact CVSS v3.0 Base Score: 6.5 Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: None Scope: Unchanged Confidentiality: High Integrity: None Availability: None Workaround There is no workaround.

open_in_new Read original post