CVE-2026-30877
Summary
The latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality.
Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS.
Details
Please refer to the attached materials.
OSコマンドインジェクション(baserCMSのアップデート機能).pdf
Impact
An authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/baserproject/basercms/security/advisories/GHSA-m9g7-rgfc-jcm7, https://nvd.nist.gov/vuln/detail/CVE-2026-30877, https://basercms.net/security/JVN_20837860, https://github.com/baserproject/basercms, https://github.com/baserproject/basercms/releases/tag/5.2.3
