GHSA-9hvg-qw5q-wqwp
Summary
SSTI is possible in Bagisto via type parameter can lead to RCE and other exploitations.
Details
- Go to
http://127.0.0.1:8000/admin/reporting/products/view?type={{7*7}}
<img width="1251" height="282" alt="image" src="https://github.com/user-attachments/assets/652e96f4-631e-4322-8561-63f4d897a480" />
Impact
Can lead to RCE, command injection.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/bagisto/bagisto/security/advisories/GHSA-9hvg-qw5q-wqwp, https://nvd.nist.gov/vuln/detail/CVE-2026-21450, https://github.com/bagisto/bagisto/commit/3f294b4837595929107d9c1bbd6d5b1222ef9fea, https://github.com/bagisto/bagisto, https://github.com/bagisto/bagisto/releases/tag/v2.3.10
