A vulnerability was found in HashBrownCMS HashBrown CMS up to 1.4.6. It has been classified as critical. This affects the function
Media.generateThumbnail of the file src/Server/Entity/Resource/Media.js of the component Media Upload Thumbnail Generation. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-70374. It is possible to initiate the attack remotely. There is no exploit available.