๐Ÿ” CVE Alert

CVE-2026-77939

MEDIUM 6.5

Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage exposed application objects including filesystem() and serializers() within the evaluation scope to read arbitrary server files and achieve conditional remote code execution if a PHP file can be placed on disk through a secondary vector.

CWE CWE-94 CWE-1336
Vendor flextype
Product flextype
Published Aug 28, 2026
Last Updated Aug 29, 2026
Stay Ahead of the Next One

Get instant alerts for flextype flextype

Be the first to know when new medium vulnerabilities affecting flextype flextype are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

flextype / flextype
0 โ‰ค 1.0.0-dev 0 โ‰ค aea4ead8c449ea5517ed53b6dcbd28b0a528ad9d

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flextype/flextype/issues/595 vulncheck.com: https://www.vulncheck.com/advisories/flextype-cms-dev-rce-via-post-api-v1-query-endpoint

Credits

Marxabo Keldibekova