Code Injection Vulnerability in SPIP by SPIP Team

⚠️ CVE-Referenzen: CVE-2026-66738
Spip - Spip - CRITICAL - CVE-2026-66738. A critical code injection vulnerability exists in SPIP versions prior to 4.4.18, specifically in installations using SQLite. The issue arises in the navigation menu endpoint, where the system fails to properly sanitize array-typed user input. This flaw allows an authenticated attacker, possessing at least editor-level privileges, to craft and submit a GET request that executes arbitrary OS commands on the web server. Notably, installations backed by MySQL are not impacted by this vulnerability. Proper patching and adherence to security best practices are crucial to mitigate potential threats.
Quelle: securityvulnerability.io