{"id":"CVE-2026-30877","aliases":["GHSA-m9g7-rgfc-jcm7"],"url":"https://o3.security/vulnerability/CVE-2026-30877","summary":"baserCMS: OS Command Injection in the baserCMS Update Functionality","details":"### Summary\nThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality.\nDue to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS.\n\n### Details\nPlease refer to the attached materials.\n[OSコマンドインジェクション（baserCMSのアップデート機能）.pdf](https://github.com/user-attachments/files/25468689/OS.baserCMS.pdf)\n\n\n\n### Impact\nAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS.","published":"2026-03-31T00:45:09.718Z","modified":"2026-08-12T03:51:31.610946582Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"baserproject/basercms","fixedVersion":"5.2.3"}],"fix":null,"references":[{"type":"WEB","url":"https://basercms.net/security/JVN_20837860"},{"type":"WEB","url":"https://github.com/baserproject/basercms/releases/tag/5.2.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30877.json"},{"type":"ADVISORY","url":"https://github.com/baserproject/basercms/security/advisories/GHSA-m9g7-rgfc-jcm7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30877"},{"type":"PACKAGE","url":"https://github.com/baserproject/basercms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.610946582Z"}}