CVE-2026-70374: Hashbrowncms Hashbrown-CMS
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec ('convert ' + tempFile + ...).
Affected products
- Hashbrowncms Hashbrown-CMS: up to and including 1.4.6
Published 2026-08-05. Last modified 2026-08-28.