Expression Language Injection Vulnerability in Flextype CMS by Flextype
CVE-2026-77939

7.1HIGH

Key Information:

Vendor

Flextype

Status
Vendor
CVE Published:
28 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-77939?

Flextype CMS through v1.0.0-dev is vulnerable to an expression language injection flaw that permits authenticated users with a valid API token to exploit the system. By submitting unsanitized input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint, attackers can gain access to arbitrary files on the server. The exposed application objects such as filesystem() and serializers() can be leveraged to read sensitive server files. Furthermore, if the vulnerability is combined with a secondary vector that allows uploading PHP files, it can lead to remote code execution.

Affected Version(s)

flextype 0 <= 1.0.0-dev

flextype 0 <= 1.0.0-dev

flextype 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marxabo Keldibekova
.