Bagisto SSTI vulnerability in type parameter can lead to RCE
Description
Published by the National Vulnerability Database
Jan 2, 2026
Published to the GitHub Advisory Database
Jan 2, 2026
Reviewed
Jan 2, 2026
Last updated
Jan 2, 2026
Summary
SSTI is possible in Bagisto via type parameter can lead to RCE and other exploitations.
Details
http://127.0.0.1:8000/admin/reporting/products/view?type={{7*7}}Impact
Can lead to RCE, command injection.
References