← Back to search

CVE-2026-70375

8.8 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
HashBrown CMS through 1.4.6 allows attackers to inject OS commands via the branch parameter, leading to potential remote code execution.
Exploitability
Exploitation requires access to the Git deployer component and knowledge of the specific branch parameter. Precondition is the presence of unescaped user input in shell commands.
Blast radius
If exploited, this vulnerability could lead to full control of the affected system, including data theft, service disruption, and lateral movement within the network.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to HashBrown CMS 1.4.7 or later.
rceos-command-injectionweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.