Vulnérabilité dans SPIP (21 août 2026)
A remote code execution vulnerability has been discovered in SPIP, allowing attackers to execute arbitrary code from a remote location. The vulnerability is currently being actively exploited, and users of SPIP versions prior to 4.4.21 are strongly advised to apply the latest security update immediately.
A remote code execution vulnerability has been identified within the SPIP content management system. This vulnerability enables an attacker to execute arbitrary code on a victim's server without requiring local access. The SPIP team has confirmed that this vulnerability is currently being actively exploited. The vulnerability stems from a flaw in how SPIP handles certain user-supplied data, leading to the execution of malicious code. Users running SPIP versions prior to 4.4.21 are at significant risk. The security team recommends consulting the SPIP security bulletin for the latest patch and mitigation steps. The bulletin can be found at https://blog.spip.net/Mise-a-jour-critique-de-securité-sortie-de-SPIP-4-4-21.html.