CVE-2026-46394 is an OS command injection vulnerability in the HAX CMS PHP backend prior to version 26.0.0. The flaw is in the Git.php library, where the application builds shell command strings from attacker-controllable input and executes them via proc_open() without proper sanitization. According to the provided content, 17 functions invoke shell commands and only the commit() function correctly applies escapeshellarg(), indicating broad unsafe command construction across the Git integration. An attacker able to influence parameters passed into Git-related operations can inject arbitrary operating system commands and have them executed in the context of the web server process. The issue can be chained with a separate configuration-manipulation vulnerability to achieve full remote code execution and complete system compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small PoC repository with 3 files: LICENSE, README.md, and a single PHP exploit script (poc_git_cmdi.php). The repository targets CVE-2026-46394 in elmsln HAXcms, specifically OS command injection in the PHP backend library system/backend/php/lib/Git.php. The README documents the root cause: multiple Git wrapper methods build raw shell command strings and pass them through run() -> run_command() -> proc_open() without escapeshellarg(), enabling arbitrary command execution when attacker-controlled values contain shell metacharacters. It also enumerates affected methods such as create_branch, delete_branch, checkout, merge, push, pull, log, show, list_tags, clone_to, clone_from, clone_remote, set_remote, rm, and partially add_tag. The PHP PoC is operational rather than just illustrative: it locates a local copy of the vulnerable Git.php via environment variable, CLI argument, or common relative paths; loads the real HAXcms Git library; creates a temporary git repository; makes an initial commit; and then exercises the vulnerable create_branch() path with an OS-specific injected payload. The payload appends a shell command that writes a marker file (PWNED.txt), then the script verifies the file exists and prints confirmation. It also includes cleanup logic to remove the proof file and temporary repository afterward. Attack-wise, this is primarily a local PoC harness for demonstrating a web-application vulnerability in HAXcms. The README further explains realistic exploitation in deployed HAXcms instances by chaining path traversal/config poisoning into Git.php command injection via manifest-controlled branch or remote settings. No hardcoded C2 or external callback infrastructure is present; the only network-relevant observables are GitHub repository URLs used in documentation. Overall, this is a legitimate exploit PoC for authenticated/authorized testing of unpatched HAXcms installations or local source checkouts.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.