Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77939— Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint

Quick assessment

Affected
flextype flextype
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Flextype CMS 在 v1.0.0-dev 及更早版本中存在表达式语言注入漏洞。持有有效 API 令牌的认证攻击者可以通过 POST /api/v1/query 端点,将未经过滤的用户输入传递给 Symfony ExpressionLanguage 引擎,从而读取任意文件。攻击者可以利用评估作用域中暴露的应用对象(包括 filesystem() 和 serializers())来读取服务器上的任意文件;如果能够通过次要向量将 PHP 文件写入磁盘,则可进一步实现有条件的远程代码执行(RCE)。

CVSS 6.5 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
flextype flextype ≤ 1.0.0-dev affected
≤ aea4ead8c449ea5517ed53b6dcbd28b0a528ad9d affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77939

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage exposed application objects including filesystem() and serializers() within the evaluation scope to read arbitrary server files and achieve conditional remote code execution if a PHP file can be placed on disk through a secondary vector.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
flextype flextype 0 ~ 1.0.0-dev -

II. Public POCs for CVE-2026-77939

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77939

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77939 (1)

Other References for CVE-2026-77939 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77939

No comments yet


Leave a comment