CamaleonCMS 2.9.1 contains a server-side template...
High severity
Unreviewed
Published
Aug 12, 2026
to the GitHub Advisory Database
•
Updated Aug 12, 2026
Description
Published by the National Vulnerability Database
Aug 12, 2026
Published to the GitHub Advisory Database
Aug 12, 2026
Last updated
Aug 12, 2026
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user.
References