CVE-2026-77939 | Flextype up to 1.0.0-dev Symfony ExpressionLanguage Engine /api/v1/query code injection

SecurityVulns

A vulnerability was found in Flextype up to 1.0.0-dev. It has been declared as critical. This impacts an unknown function of the file /api/v1/query of the component Symfony ExpressionLanguage Engine. Such manipulation leads to code injection.

This vulnerability is listed as CVE-2026-77939. The attack may be performed from remote. There is no available exploit.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More