Skip to main content
HIGH

CVE-2026-70375

CVSS v3

8.8

HIGH

EPSS Score

1.9 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote character in the repo, branch, username, and password fields; shell metacharacters such as ';', '&&', '|',

Technical details

Published
2026-08-05
Last Modified
2026-08-05

Frequently asked questions

What is CVE-2026-70375?

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote character in the repo, branch, username, and password fields; shell metacharacters such as ';', '&&', '|',

Is CVE-2026-70375 actively exploited?

Active exploitation of CVE-2026-70375 has not been confirmed. Its EPSS score was 1.9% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-70375?

CVE-2026-70375 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2026-70375 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key