CVE-2026-31020 affects DocsGPT version 0.15.0 and below, exposing a critical server-side template injection (SSTI) vulnerability. The application's custom prompt feature renders user-supplied content through Jinja templates without any input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions into the chatbot prompt interface. Successful exploitation leads to full remote code execution (RCE) on the server. The vulnerability requires no authentication, significantly lowering the barrier for exploitation. The affected vendor is arc53, the developer of DocsGPT. A proof-of-concept has been published on GitHub. Organizations using DocsGPT 0.15.0 or earlier should prioritize patching or mitigation immediately.