CVE-2026-70375: Hashbrowncms Hashbrown-CMS
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.
Affected products
- Hashbrowncms Hashbrown-CMS: up to and including 1.4.6
Published 2026-08-05. Last modified 2026-08-28.