CVE-2026-21450
EPSS 0.62%Bagisto SSTI vulnerability in type parameter can lead to RCE
Published: 1/2/2026Modified: 2/3/2026
Also known as:GHSA-9hvg-qw5q-wqwp
Description
### Summary SSTI is possible in Bagisto via type parameter can lead to RCE and other exploitations. ### Details 1. Go to `http://127.0.0.1:8000/admin/reporting/products/view?type={{7*7}}` <img width="1251" height="282" alt="image" src="https://github.com/user-attachments/assets/652e96f4-631e-4322-8561-63f4d897a480" /> ### Impact Can lead to RCE, command injection.
Affected packages (1)
- Packagist/bagisto/bagistofrom 0, < 2.3.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2026-21450
- PATCHhttps://github.com/bagisto/bagisto
- WEBhttps://github.com/bagisto/bagisto/commit/3f294b4837595929107d9c1bbd6d5b1222ef9fea
- WEBhttps://github.com/bagisto/bagisto/releases/tag/v2.3.10
- WEBhttps://github.com/bagisto/bagisto/security/advisories/GHSA-9hvg-qw5q-wqwp