{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azeroxzerox1.1.20/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zerox:zerox:1.1.20:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85672"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zerox (1.1.20)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-85672","command-injection","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["zerox"],"content_html":"\u003cp\u003eZerox version 1.1.20 contains a critical OS command injection vulnerability within its file download mechanism. The flaw exists because the library derives temporary file extensions directly from provided document URLs without proper sanitization. These extensions are then interpolated into system shell commands that invoke poppler utilities for document processing.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by supplying a crafted URL where the file extension portion includes shell command substitution syntax (e.g., $(command)). When the application attempts to download or process the document, the underlying shell executes the injected payload before the processing task proceeds. This allows for unauthenticated arbitrary OS command execution on the host running the zerox-dependent service. Given that this component is often used in automated document ingestion pipelines, the impact is significant, potentially leading to full system compromise or lateral movement from the processing environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution with the privileges of the application process. This impacts any server or containerized environment utilizing zerox 1.1.20 to process remote documents. Given the nature of command injection in document parsing pipelines, an attacker could potentially exfiltrate sensitive files, pivot into internal network segments, or deploy further malware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of zerox beyond 1.1.20 that addresses this sanitization flaw.\u003c/li\u003e\n\u003cli\u003eAudit logs for process creation events originating from the application process that invoke shell command substitutions or unexpected poppler-related binaries.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for all URLs submitted to the document ingestion pipeline to ensure no shell metacharacters are present.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:26:22Z","date_published":"2026-09-04T15:26:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zerox-rce/","summary":"The zerox library version 1.1.20 is susceptible to OS command injection via maliciously crafted URLs that interpolate unsanitized file extensions into shell-executed poppler utility commands.","title":"CVE-2026-85672 OS Command Injection in zerox","url":"https://feed.craftedsignal.io/briefs/2026-09-zerox-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zerox:zerox:1.1.20:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}