CVE-2026-66738

NameCVE-2026-66738
DescriptionSPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET request to /ecrire/?exec=navigation to execute arbitrary OS commands in the web server process. MySQL-backed installations are not affected.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6435-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
spip (PTS)bullseye3.2.11-3+deb11u10vulnerable
bullseye (security)3.2.11-3+deb11u7vulnerable
trixie4.4.15+dfsg-0+deb13u1vulnerable
trixie (security)4.4.19+dfsg-0+deb13u1fixed
forky4.4.16+dfsg-1vulnerable
sid4.4.19+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
spipsourcetrixie4.4.19+dfsg-0+deb13u1DSA-6435-1
spipsource(unstable)4.4.18+dfsg-1

Notes

https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html

Search for package or bug name: Reporting problems