CVE-2026-82666: yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection
A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin Theme Editor. This manipulation of the argument blade causes code injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 2.1.1 is capable of addressing this issue. Patch name: 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
yaojingang GEOFlow Superadmin Theme Editor (SiteThemeEditorController.php)to a version that resolves this vulnerability.Fixed in 2.1.1Patch 67abfd864a15d169a78429f3290c91cb3b93e849
Event History
Frequently Asked Questions
Which deployments are affected?
yaojingang GEOFlow versions up to and including 2.1.0 are affected when the Superadmin Theme Editor component is present.
What access does an attacker need to exploit this issue?
The vulnerable preview function can be reached remotely, but the supplied severity vector indicates that high privileges are required. No user interaction is required.
Is public exploit code available?
Yes. The vulnerability data states that an exploit has been published and may be used.
How should this be remediated?
Upgrade GEOFlow to version 2.1.1. The provided patch identifier is 67abfd864a15d169a78429f3290c91cb3b93e849.