CVE-2026-77939
Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage exposed application objects including filesystem() and serializers() within the evaluation scope to read arbitrary server files and achieve conditional remote code execution if a PHP file can be placed on disk through a secondary vector.
| CWE | CWE-94 CWE-1336 |
| Vendor | flextype |
| Product | flextype |
| Published | Aug 28, 2026 |
| Last Updated | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for flextype flextype
Be the first to know when new medium vulnerabilities affecting flextype flextype are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
flextype / flextype
0 โค 1.0.0-dev 0 โค aea4ead8c449ea5517ed53b6dcbd28b0a528ad9d
References
Credits
Marxabo Keldibekova