CVE-2026-77939 | Flextype up to 1.0.0-dev Symfony ExpressionLanguage Engine /api/v1/query code injection
A vulnerability was found in Flextype up to 1.0.0-dev. It has been declared as critical. This impacts an unknown function of the file /api/v1/query of the component Symfony ExpressionLanguage Engine. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2026-77939. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More