Junglewise Threat Intelligence

CVE-2026-39394: ci4-cms-erp CI4MS CRLF injection in Install controller

CVE-2026-39394 · Severity: high · CVSS 8.1 · Published 2026-04-08

Technologies: ci4-cms-erp/ci4ms (Packagist), Ci4-Cms-Erp Ci4ms. Vendors: Packagist.

Executive brief

CI4MS, a content management system framework, contains a vulnerability in its installation component that allows unauthorized users to modify the application's core configuration file (.env). By sending specially crafted web requests, an attacker can hijack the application's URL, disable security features, or cause a service outage. This can occur during a new installation or if the system's internal cache expires, potentially leading to full site takeover or redirection of users to malicious domains.

Technical details

The Install::index() controller in CI4MS fails to validate the 'host' POST parameter before passing it to updateEnvSettings(), which uses preg_replace() to write values into the .env file. Because newline characters are not stripped, an attacker can inject arbitrary key-value pairs (CRLF injection) to override application settings like 'app.baseURL' or security headers. The vulnerability is exploitable when the 'InstallFilter' is bypassed, which occurs during fresh deployments or when the 'settings' cache is empty. Additionally, CSRF protection is explicitly disabled on the affected routes, allowing for remote exploitation via a victim's browser. The issue is resolved in version 0.31.4.0 by adding regex validation for the host parameter and stripping newlines during the file update process.

Affected products

  • ci4-cms-erp CI4MS < 0.31.4.0

Timeline

  • 2026-04-07: advisory: GitHub Security Advisory published
  • 2026-04-08: disclosed: CVE-2026-39394 published
  • 2026-04-08: patched: Fixed in version 0.31.4.0

References

Related threats