Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users
Description
Published by the National Vulnerability Database
Jan 2, 2026
Published to the GitHub Advisory Database
Jan 2, 2026
Reviewed
Jan 2, 2026
Last updated
Jan 8, 2026
Summary
SSTI is possible via first name and last name parameters provided by lowest-privileged users.
Details
http://127.0.0.1:8000/and login or signuphttp://127.0.0.1:8000/customer/account/profilePOC
Impact
This can lead to RCE, command injection.
References