Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injectionReferenceshttps://www.gbif.org/ipthttps://github.com/gbif/ipt/issues/3118https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0016.md