A critical Remote Code Execution (RCE) vulnerability exists in DSpace, an open-source repository application. The flaw affects versions 8.0-rc1 through before 8.4, versions 9.0-rc1 through before 9.3, and version 10-rc1. The vulnerability is exploitable via Velocity Templates used by DSpace for COAR Notify and LDN (Linked Data Notifications) messages. Successful exploitation could allow an attacker to execute arbitrary code on the affected server. The issue has been addressed and patched in DSpace versions 8.4, 9.3, and 10.0. Users are strongly advised to upgrade to the patched versions immediately. The vulnerability was tracked and disclosed through GitHub security advisories and NVD.