Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-77647: SPIP before 4.4.20 lets attackers run code
CVE-2026-77647 · published 14 days ago
Summary
Websites using SPIP versions older than 4.4.20 can be accessed by anyone on the internet who can then cause the server to run their own programs. This happens because the software misinterprets certain code blocks, allowing malicious input to be executed. Upgrade SPIP to version 4.4.20 or later, or apply the provided security patch, to stop this risk.
What to do
- Update debian spip to version 4.4.20+dfsg-0+deb13u1.
- Update spip spip to version 4.4.20 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | spip | spip | < 4.4.20 |
| Debian:11 | debian | spip | All versions |
| Debian:13 | debian | spip |
< 4.4.20+dfsg-0+deb13u1 Fix: upgrade to 4.4.20+dfsg-0+deb13u1
|
| Debian:14 | debian | spip | All versions |
Original advisory text
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_e...
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 3%
Type
CWE-94Code Injection
Timeline
Published20 Aug 2026
Updated2 Sep 2026
First seen20 Aug 2026
Monitor software like this
Free during beta