{"id":"CVE-2023-29689","details":"PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.","aliases":["GHSA-w7vm-4v3j-vgpw"],"modified":"2026-08-12T03:51:09.536468975Z","published":"2023-08-04T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29689.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/174088/Pyro-CMS-3.9-Server-Side-Template-Injection.html"},{"type":"WEB","url":"https://cupc4k3.lol/ssti-leads-to-rce-on-pyrocms-7515be27c811"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29689.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29689"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pyrocms/pyrocms","events":[{"introduced":"6f17a11f623f6fa0216449fc5558ea1ce9b595cd"},{"last_affected":"6f17a11f623f6fa0216449fc5558ea1ce9b595cd"}],"database_specific":{"extracted_events":[{"introduced":"3.9"},{"last_affected":"3.9"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:pyrocms:pyrocms:3.9:*:*:*:*:*:*:*"}}],"versions":["3.9","v3.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29689.json"}}],"schema_version":"1.9.0"}