Affected versions and impact
HubSpot Jinjava is affected in versions >= 2.7.0 and < 2.7.5, and in version 2.8.0. The JavaType deserialization sandbox bypass can enable sandbox escape primitives such as arbitrary file reads or SSRF and, in some deployments, follow-on remote code execution. RCE is not guaranteed: impact depends on how the application uses Jinjava and whether untrusted templates can reach the affected behavior [S1][S2][S3].
How FixVibe covers it
FixVibe's repository scans flag Maven and Gradle projects that resolve an affected com.hubspot.jinjava:jinjava version, reported as a version-based advisory with the version and file.
Remediation
Upgrade to Jinjava 2.7.5 or 2.8.1, or the current supported release, then rebuild and verify the dependency tree and deployed runtime. Restrict untrusted template input and review where template rendering is reachable. Follow the HubSpot advisory and the linked ecosystem records for release-specific guidance [S1][S2][S3][S4].
