CVE-2023-29689

CRITICAL

PyroCMS 3.9 - Remote Code Execution via Server-Side Template Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-29689. PoCs published by Daniel Barros, YSaxon.

AI-analyzed exploit summary This exploit demonstrates a Server-Side Template Injection (SSTI) vulnerability in Pyro CMS 3.9, allowing authenticated users to execute arbitrary commands by injecting malicious templates into the role description field.

Description

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

Exploits (2)

exploitdb WORKING POC
by Daniel Barros · textwebappspython
https://www.exploit-db.com/exploits/51669

This exploit demonstrates a Server-Side Template Injection (SSTI) vulnerability in Pyro CMS 3.9, allowing authenticated users to execute arbitrary commands by injecting malicious templates into the role description field.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pyro CMS 3.9
Auth required
Prerequisites: Valid admin credentials · Access to the admin panel
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by YSaxon · poc
https://github.com/YSaxon/pyrocms-ssti-fix

This repository provides a legitimate security fix for CVE-2023-29689, a Server-Side Template Injection (SSTI) vulnerability in PyroCMS 3.9. It implements a Twig sandbox to restrict dangerous operations in user-editable templates while allowing safe functionality.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PyroCMS 3.9
Auth required
Prerequisites: Admin access to PyroCMS · Twig 2.16+ or 3.9+ · PHP 7.4+ or 8.0+
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.6082
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

Status published
Products (2)
pyrocms/pyrocms 3.9
pyrocms/pyrocms 0Packagist
Published Aug 04, 2023
Tracked Since Feb 18, 2026