CyberRota Analysis
AI-GeneratedSPIP versions prior to 4.4.21 are vulnerable to unauthenticated remote code execution due to improper handling of the X-Spip-Filtre HTTP request header, allowing attackers to inject malicious code. This critical vulnerability has been actively exploited in the wild, posing significant risks to any installations of SPIP. Organizations using SPIP should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.