{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cachet--2.4.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-69118"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cachet (\u003c= 2.4.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Cachet"],"content_html":"\u003cp\u003eCachet versions 2.4.1 and earlier contain a server-side template injection (SSTI) vulnerability during the processing of incident templates. The application fails to properly sanitize user-supplied input when rendering these templates, which rely on the Blade templating engine or Twig filters. An authenticated user with sufficient permissions to create or modify incident templates can inject malicious syntax that is subsequently executed by the application's template engine. This allows an attacker to execute arbitrary PHP code under the context of the web server process, potentially leading to a full system compromise. The vulnerability is critical for organizations that allow users with incident management roles to modify global or incident-specific templates.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary remote code execution on the server hosting the Cachet instance. This can lead to complete loss of confidentiality, integrity, and availability of the application and the underlying server. Impact includes potential unauthorized data access, lateral movement within the network, and the deployment of persistent backdoors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Cachet instances to the latest available patched version to remediate the vulnerability.\u003c/li\u003e\n\u003cli\u003eReview all incident templates for unauthorized modifications, specifically looking for Blade or Twig directives, such as {{ }} or {!! !!}, that contain non-standard PHP functions.\u003c/li\u003e\n\u003cli\u003eRestrict the ability to create and modify incident templates to highly trusted administrative accounts only.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect POST requests directed at template management endpoints for common template injection characters and strings.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:36:39Z","date_published":"2026-08-10T21:36:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cachet-ssti/","summary":"Cachet versions 2.4.1 and earlier are vulnerable to server-side template injection in incident template rendering, allowing authenticated attackers to execute arbitrary system commands.","title":"Remote Code Execution via SSTI in Cachet","url":"https://feed.craftedsignal.io/briefs/2026-08-cachet-ssti/"}],"language":"en","title":"CraftedSignal Threat Feed - Cachet (\u003c= 2.4.1)","version":"https://jsonfeed.org/version/1.1"}