CVE-2026-70375

Summary

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.

Affected Software

VendorProductVersion RangeStatus
HashBrownCMShashbrown-cms0 <= 1.4.6affected

Weaknesses

  • CWE-78: CWE-78 OS Command Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References