Impact
Cachet releases up to version 2.4.1 allow an authenticated user to inject malicious content into incident templates. The vulnerable rendering process accepts Blade directives or Twig filters that, when processed, execute system commands, giving the attacker control over the web server process. This flaw is a classic server‑side template injection that can enable full remote code execution. The primary weakness is identified by CWE‑1336, with CWE‑863 indicating potential data leakage or unsanitized input handling.
Affected Systems
The affected vendor is CachetHQ, producing the Cachet status‑page software. Versions up to and including 2.4.1 are impacted, meaning any deployment running Cachet 2.4.1 or earlier is vulnerable.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is considered high severity. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog. The attack requires legitimate user credentials to create a malicious incident template and then create or trigger an incident where the template is rendered. Once the template is executed, the attacker gains remote code execution as the web server user. The lack of exploitation probability data means the risk should be treated as actionable, and the high impact warrants immediate attention.
OpenCVE Enrichment