Description
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template references a user-controlled token (such as #ActingUserName# or #UserName#, populated from a member's display name), an authenticated member can set their display name to JSON metacharacters and inject arbitrary key-value pairs into the rendered payloads delivered to webhook, SIEM, Slack, Teams, or Datadog endpoints, making injected fields indistinguishable from legitimate template output.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Confidentiality (Vulnerable System)
None
Integrity (Vulnerable System)
Low
Availability (Vulnerable System)
None
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
Low
Availability (Subsequent System)
None
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None
Affected products
- bitwarden / server0 – 2026.5.0
References
- MISChttps://sanjokkarki.com.np/blog/bitwarden-webhook-json-injection
- PATCHhttps://github.com/bitwarden/server/releases/tag/v2026.5.0
- PATCHhttps://github.com/bitwarden/server/pull/7593
- PATCHhttps://github.com/bitwarden/server/commit/a26afd18130ef985ede5c97d277820d045185a28
- VENDOR_ADVISORYhttps://www.vulncheck.com/advisories/bitwarden-server-json-injection-via-webhook-templates