{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/syspass/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-63725"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["sysPass"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["sysPass"],"content_html":"\u003cp\u003eCVE-2026-63725 is a command injection vulnerability affecting the sysPass password management software. The vulnerability originates in the \u003ccode\u003eFileBackupService::doBackupFiles()\u003c/code\u003e method located in \u003ccode\u003elib/SP/Services/Backup/FileBackupService.php\u003c/code\u003e. The application improperly handles the \u003ccode\u003e$this-\u0026gt;path\u003c/code\u003e variable, which stores the backup directory path, by concatenating it directly into a \u003ccode\u003etar\u003c/code\u003e command string passed to PHP's \u003ccode\u003eexec()\u003c/code\u003e function without sanitization via \u003ccode\u003eescapeshellarg()\u003c/code\u003e. Because the backup path is a configurable setting stored in the database and accessible via the admin API or UI, an attacker with administrative privileges can inject arbitrary shell metacharacters. Upon triggering a backup operation, these metacharacters are executed in the context of the web server process (e.g., \u003ccode\u003ewww-data\u003c/code\u003e or \u003ccode\u003eapache\u003c/code\u003e). As sysPass contains sensitive credentials and encryption keys, successful exploitation grants the attacker full control over the password vault, potential lateral movement into managed systems, and the ability to establish persistent access on the host.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full compromise of the sysPass instance. As a password manager, the application stores critical credentials and encryption keys; an attacker can decrypt the entire database, exfiltrate all stored passwords, pivot to managed internal environments using those credentials, and deploy web shells or other backdoors on the host server to maintain persistence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided patch to \u003ccode\u003elib/SP/Services/Backup/FileBackupService.php\u003c/code\u003e to ensure the backup path is correctly sanitized using \u003ccode\u003eescapeshellarg()\u003c/code\u003e before string concatenation.\u003c/li\u003e\n\u003cli\u003eAudit administrative account activity and API token usage to detect unauthorized modifications to sysPass configuration settings.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the sysPass web interface and API to a limited set of known-good IP addresses or via an authenticated VPN.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T23:31:10Z","date_published":"2026-08-06T23:31:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-63725/","summary":"An authenticated command injection vulnerability (CVE-2026-63725) in sysPass allows administrative users to execute arbitrary OS commands through unsanitized backup path configurations.","title":"Command Injection in sysPass via FileBackupService","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-63725/"}],"language":"en","title":"CraftedSignal Threat Feed - SysPass","version":"https://jsonfeed.org/version/1.1"}