THREAT OPS › Threat News › [NVD] CVE-2026-70375 (HIGH 8.8) — HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command w
[NVD] CVE-2026-70375 (HIGH 8.8) — HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command w
CVE-2026-70375 CVSS: 8.8 HIGH Published: 2026-08-05T07:16:39.697
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.
Indicators of compromise
- CVE-2026-70375cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70375