PatchSiren

cachethq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cachethq CVE published 2026-08-10

CVE-2026-69118

CVE-2026-69118 is a server-side template injection vulnerability in Cachet through version 2.4.1. Authenticated users can execute arbitrary PHP code by creating malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process. This vulnerability allows attackers to create malicious incident [truncated]