Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian Trixie SPIP Critical Remote Code Exec Vulnerabilities DSA-6296-1

debian
Calendar Grey May 25, 2026
Debian Logo
Multiple vulnerabilities in SPIP fixed with new updates for Debian Trixie users. Includes critical remote code execution risk.
Multiple vulnerabilities were discovered in SPIP, a website engine for publishing, which may result in remote code execution or an open redirect

Summary

For the stable distribution (trixie), these problems have been fixed in
version 4.4.15+dfsg-0+deb13u1.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/spip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: spip
CVE ID: CVE-2026-8429 CVE-2026-8430 CVE-2026-48832

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here