Two security vulnerabilities have been disclosed in Tryton's server component (trytond). The first (issue #5160) allows users in the administrator group to execute arbitrary Python code on the server via malicious report templates. The second (issue #14869) extends this attack surface to the marketing group through uploaded marketing email templates. Both are remote code execution via template injection with a CVSS v3.0 base score of 6.5. There is no workaround — affected users must upgrade trytond to versions 8.0.6, 7.8.12, or 7.0.53 or later depending on their series. Note that some custom reports using dynamic or private attributes may break after upgrading and will need to be updated.
255 Impressions