CVE-2026-70375 | HashBrown CMS up to 1.4.6 Git Deployer GitDeployer.js GitDeployer.pullRepo branch os command injection
A vulnerability was found in HashBrown CMS up to 1.4.6. It has been declared as problematic. This vulnerability affects the function GitDeployer.pullRepo of the file src/Server/Entity/Deployer/GitDeployer.js of the component Git Deployer. The manipulation of the argument branch results in os command injection.
This vulnerability is known as CVE-2026-70375. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More