{"id":"GHSA-qxmc-6f24-g86g","summary":"baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)","details":"## Summary\n\nIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the `exec()` function without proper validation or escaping. This issue allows **an authenticated CMS administrator to execute arbitrary OS commands on the server (Remote Code Execution, RCE)**.\n\nThis vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from **a design that directly executes input values received on the server side as OS commands**. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, **an attack is possible as long as a request containing a valid token is processed within an administrator session**.\n\n---\n\n## Vulnerability Information\n\n| Item | Details |\n| ---- | ------- |\n| CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command |\n| Impact | Remote Code Execution (RCE) |\n| Severity | Critical |\n| Attack Requirements | Administrator privileges required |\n| Reproducibility | Reproducible (confirmed multiple times) |\n| Test Environment | baserCMS 5.2.2 (Docker / development environment) |\n\n---\n\n## Affected Areas\n\n- **Controller**\n  - `PluginsController::get_core_update()`\n- **Service**\n  - `PluginsService::getCoreUpdate()`\n- **Affected Endpoint**\n  - `/baser/admin/baser-core/plugins/get_core_update`\n\n---\n\n## Technical Details\n\n### Vulnerable Code Flow\n\n```text\nPluginsController::get_core_update()\n  ↓ Retrieves php parameter from POST data\nPluginsService::getCoreUpdate($targetVersion, $php, $force)\n  ↓ Concatenates $php into command string without validation or escaping\nexec($command)\n```\n\n### Relevant Code (Excerpt)\n\n**PluginsController.php**\n\n```php\n$service-\u003egetCoreUpdate(\n    $request-\u003egetData('targetVersion') ?? '',\n    $request-\u003egetData('php') ?? 'php',\n    $request-\u003egetData('force'),\n);\n```\n\n**PluginsService.php**\n\n```php\n$command = $php . ' ' . ROOT . DS . 'bin' . DS . 'cake.php composer ' .\n           $targetVersion . ' --php ' . $php . ' --dir ' . TMP . 'update';\n\nexec($command, $out, $code);\n```\n\nThe `$php` parameter is user input, and **none** of the following countermeasures are in place:\n\n- Restriction via allowlist\n- Validation via regular expression\n- Escaping via `escapeshellarg()` or similar\n\n---\n\n## Attack Scenario\n\n1. The attacker logs in as a CMS administrator\n2. Sends a POST request to the core update functionality in the admin panel\n3. Specifies a string containing OS commands in the `php` parameter\n4. `exec()` is executed on the server side, running the arbitrary OS command\n\n### Example Attack Input (Conceptual)\n\n```text\nphp=php;id\u003e/tmp/rce_test;#\n```\n\n---\n\n## Verification Results (PoC)\n\n### Execution Result\n\n```bash\n$ docker exec bc-php cat /tmp/rce_test\nuid=1000(www-data) gid=1000(www-data) groups=1000(www-data)\n```\n\nThe above confirms that OS commands can be executed with `www-data` privileges.\n\n### Additional Notes\n\n- Reproducible through the legitimate flow in the admin panel (browser)\n- Succeeds even with CSRF/FormProtection tokens included in a legitimate request\n- Failure cases (400/403) have also been investigated and differentiated\n- Confirmed reproducible via resending HTTP requests with tools such as curl (resending the same request containing valid tokens)\n\n---\n\n## Impact\n\nIf this vulnerability is exploited, the following becomes possible:\n\n- Retrieval of server information\n- Reading/writing arbitrary files\n- Retrieval of application configuration information (DB credentials, etc.)\n- OS-level operations beyond application permission boundaries\n\nAlthough administrator privileges are required, **this is a design issue where the impact extends from the application layer to the OS layer**, and the impact is considered significant.\n\n---\n\n## Recommended Fix\n\n### Primary Recommendation\n\n- Do not accept the PHP executable path from user input\n- Fix the PHP executable on the server side using the `PHP_BINARY` constant\n\n```php\n$php = escapeshellarg(PHP_BINARY);\n```\n\n### Supplementary Fix Recommendations\n\n- Apply `escapeshellarg()` escaping to other command-line arguments (version number, directory, etc.) as well\n- If possible, consider using execution methods that do not involve shell interpretation (array format, Process class, etc.)\n\n### Alternative (Not Recommended)\n\n- Allowlist validation for the PHP executable path\n- Combined use of regex validation and `escapeshellarg()`\n\nHowever, **from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended**.\n\n---\n\n## Additional Notes\n\n- This issue is independent of UI display controls (showing/hiding buttons)\n- As long as the endpoint exists, an attack is possible if a request containing valid tokens is processed\n- This is a problem stemming from the design-level handling of input, and cannot be prevented by CSRF or UI controls alone\n\n---\n\n## Conclusion\n\nDue to a design issue in baserCMS's core update functionality where user input is passed to `exec()` without validation, **Remote Code Execution (RCE) is achievable with administrator privileges**. This vulnerability can be fixed through input validation and design review, and prompt remediation is recommended.\n\nThis advisory was translated from Japanese to English using GitHub Copilot.","aliases":["CVE-2026-21861"],"modified":"2026-09-10T03:50:40.575249602Z","published":"2026-03-31T22:27:05Z","database_specific":{"nvd_published_at":"2026-03-31T01:16:35Z","cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-03-31T22:27:05Z"},"references":[{"type":"WEB","url":"https://github.com/baserproject/basercms/security/advisories/GHSA-qxmc-6f24-g86g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21861"},{"type":"WEB","url":"https://basercms.net/security/JVN_20837860"},{"type":"PACKAGE","url":"https://github.com/baserproject/basercms"},{"type":"WEB","url":"https://github.com/baserproject/basercms/releases/tag/5.2.3"}],"affected":[{"package":{"name":"baserproject/basercms","ecosystem":"Packagist","purl":"pkg:composer/baserproject/basercms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.3"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","1.0.0","2.0.0-rc1","2.0.0-rc2","2.0.0-rc3","2.0.0-rc4","2.0.0-rc5","2.0.0-rc6","3.0.10","3.0.10.1","3.0.11","3.0.11.1","3.0.12","3.0.13","3.0.14","3.0.15","3.0.16","3.0.17","3.0.18","3.0.19","3.0.20","3.0.21","3.0.22","3.0.23","3.0.24","3.0.25","3.0.26","3.0.7","3.0.7.1","3.0.8","3.0.8.1","3.0.9","3.0.9.1","4.0.0","4.0.0-beta","4.0.1","4.0.10","4.0.10.1","4.0.11","4.0.2","4.0.2.1","4.0.3","4.0.4","4.0.5","4.0.5.1","4.0.5.2","4.0.6","4.0.7","4.0.8","4.0.9","4.1.0","4.1.0.1","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.2.5","4.3.0","4.3.1","4.3.2","4.3.3","4.3.4","4.3.5","4.3.6","4.3.7","4.3.7.1","4.4.0","4.4.1","4.4.1.1","4.4.2","4.4.2.1","4.4.3","4.4.4","4.4.5","4.4.6","4.4.7","4.4.8","4.5.0","4.5.1","4.5.2","4.5.3","4.5.4","4.5.5","4.5.6","4.6.0","4.6.1","4.6.1.1","4.6.2","4.6.3","4.7.0","4.7.2","4.7.3","4.7.5","4.7.6","4.7.7","4.7.8","4.8.0","4.8.1","4.8.2","4.8.3","5.0.0","5.0.0-beta1","5.0.0-beta2","5.0.0-beta3","5.0.0-beta4","5.0.1","5.0.10","5.0.11","5.0.12","5.0.14","5.0.15","5.0.16","5.0.17","5.0.18","5.0.19","5.0.2","5.0.20","5.0.21","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8","5.0.9","5.1.0","5.1.1","5.1.10","5.1.2","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7","5.1.8","5.1.9","5.2.0","5.2.1","5.2.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-qxmc-6f24-g86g/GHSA-qxmc-6f24-g86g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}