Expression Language Injection Vulnerability in Flextype CMS by Flextype
CVE-2026-77939
Key Information:
Badges
What is CVE-2026-77939?
Flextype CMS through v1.0.0-dev is vulnerable to an expression language injection flaw that permits authenticated users with a valid API token to exploit the system. By submitting unsanitized input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint, attackers can gain access to arbitrary files on the server. The exposed application objects such as filesystem() and serializers() can be leveraged to read sensitive server files. Furthermore, if the vulnerability is combined with a secondary vector that allows uploading PHP files, it can lead to remote code execution.
Affected Version(s)
flextype 0 <= 1.0.0-dev
flextype 0 <= 1.0.0-dev
flextype 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
