Vendor
Cachet versions 2.4.1 and earlier are vulnerable to server-side template injection in incident template rendering, allowing authenticated attackers to execute arbitrary system commands.