PT-2026-69941 · Cachet · Cachet
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cachet versions prior to 2.4.2
Description
An issue exists in incident template rendering that allows authenticated users to perform server-side template injection. By creating malicious incident templates using Blade directives or Twig filters, an attacker can execute arbitrary PHP code and system commands when incidents are created, leading to remote code execution as the web server process.
Recommendations
Update Cachet to version 2.4.2 or later.
Exploit
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cachet