<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:filerun:filerun:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afilerunfilerun/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 19:07:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afilerunfilerun/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in FileRun</title><link>https://feed.craftedsignal.io/briefs/2026-09-filerun-rce/</link><pubDate>Thu, 10 Sep 2026 19:07:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-filerun-rce/</guid><description>FileRun versions prior to 2026.3.0 contain an OS command injection vulnerability via an improper redefinition of escapeshellcmd() that allows unauthenticated or authenticated users to execute arbitrary commands.</description><content:encoded><![CDATA[<p>FileRun versions prior to 2026.3.0 are susceptible to OS command injection due to the insecure redefinition of the PHP function 'escapeshellcmd()' within the 'CLI.php' file. This flaw effectively disables necessary character escaping for shell metacharacters, permitting unsanitized user input to reach an 'exec()' sink. The vulnerability presents two primary attack vectors: an interactive path requiring superuser privileges via 'image_preview.php' using the 'args' parameter, and a persistent vector where malicious payloads are injected into 'thumbnails_ffmpeg_args' or 'thumbnails_ffmpeg_ss'. In the latter scenario, the attacker-controlled code is executed whenever a user triggers the video thumbnail generation process, potentially leading to unauthorized system access or remote code execution.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for remote code execution on the server hosting the FileRun instance. Depending on the privileges of the web service account, this could lead to full system compromise, exfiltration of stored user data, or lateral movement within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update FileRun to version 2026.3.0 or later immediately to patch the command injection vulnerability in CLI.php.</p>
<h2 id="impact-1">Impact</h2>
<p>The vulnerability is rated with a CVSS v3.1 base score of 7.2. Organizations utilizing FileRun are at risk of remote code execution, which could result in unauthorized data access or full server takeover.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>rce</category><category>file-run</category></item></channel></rss>