Executive brief
SPIP is a website engine and content management platform used to publish and manage website content. An unauthenticated attacker can exploit a flaw in how SPIP identifies and processes PHP code blocks to execute arbitrary code on the server. This vulnerability affects all versions and was actively exploited in the wild, putting any SPIP-based website at risk of complete compromise.
Technical details
The vulnerability is a pre-authentication remote code execution (RCE) flaw resulting from incorrect identification of PHP blocks combined with improper handling of var_export in cases where a less-than character (<) is present. The flaw is universal and affects all SPIP versions without any special preconditions required. An unauthenticated, network-adjacent attacker can trigger this vulnerability to achieve arbitrary code execution on the affected server. The vulnerability is not blocked by SPIP's security screen and was patched in version 4.4.20, released on August 17, 2026, following reports of active exploitation in the wild.
Affected products
- SPIP SPIP before 4.4.20
Timeline
- 2026-08-17: disclosed: SPIP 4.4.20 released with security patch
- 2026-08-20: exploited: Active exploitation observed in the wild by August 20, 2026
- 2026-08-18: advisory: Debian Security Advisory DSA-6448-1 published