THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70375 (HIGH 8.8) — HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command w

[NVD] CVE-2026-70375 (HIGH 8.8) — HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command w

mednvdPublished 2026-08-05

CVE-2026-70375 CVSS: 8.8 HIGH Published: 2026-08-05T07:16:39.697

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70375