PatchSiren

flextype CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH flextype CVE published 2026-08-28

CVE-2026-77939

CVE-2026-77939 is an expression language injection vulnerability in Flextype CMS through v1.0.0-dev. Authenticated attackers with a valid API token can read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. This vulnerability allows attackers to leverage exposed application objects, including filesystem() and serializer [truncated]