{"id":"CVE-2026-70375","published":"2026-08-05T07:16:39.697","lastModified":"2026-08-10T12:17:23.200","description":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://cve.turansec.uz/advisories/TRN-B571F773","tags":[]},{"url":"https://github.com/HashBrownCMS/hashbrown-cms","tags":[]}],"exploitRefs":[{"url":"https://github.com/HashBrownCMS/hashbrown-cms","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows attackers to inject and execute arbitrary shell commands through the Git deployer component, leading to remote code execution.","exploitability":"Exploitation requires access to the Git branch value, making it moderately easy for an attacker with control over this parameter.","blast_radius":"If exploited, the vulnerability could lead to complete compromise of the affected system and potentially other systems in the network.","remediation":"Update HashBrown CMS to version 1.4.7 or later which includes a fix for this issue.","tags":["rce","git","shell","cms"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:47:10.935Z"}}