---
id: CVE-2026-97150
title: "When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed.\r\nArbitrary files on the system may be read or deleted by an administ…"
summary: "When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed.\r\nArbitrary files on the system may be read or deleted by an administ…"
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-829
vendor: baserCMS Users Community
product: BcAddonMigrator
affected:
  - BcAddonMigrator <= 5.2.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T08:16:36.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97150'
references:
  - url: 'https://basercms.net/security/JVN_21754394'
    label: vultures@jpcert.or.jp
  - url: >-
      https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f064c104
    label: vultures@jpcert.or.jp
  - url: 'https://jvn.jp/en/jp/JVN21754394'
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T07:59:43.041Z'
---

## Overview

When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed.
Arbitrary files on the system may be read or deleted by an administrative user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
