{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-53975/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-53975"},{"cvss":7.5,"id":"CVE-2026-53977"},{"cvss":9.1,"id":"CVE-2026-53976"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenChamber (1.11.7)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","web-vulnerability","cve-2026-53975"],"_cs_type":"advisory","_cs_vendors":["OpenChamber"],"content_html":"\u003cp\u003eOpenChamber version 1.11.7 is susceptible to a critical unauthenticated remote code execution vulnerability (CVE-2026-53975). The vulnerability exists in the /api/fs/exec endpoint, which passes user-provided input directly to the Node.js spawn() function without any validation or sanitization. Furthermore, the application's authentication middleware fails to enforce security when the UI_PASSWORD environment variable is unset. As the default Docker deployment configuration leaves this variable unconfigured, most deployments are exposed to unauthenticated exploitation. An attacker can submit a crafted POST request to trigger arbitrary command execution as the application user, resulting in the server returning the full command output, including stdout, stderr, and the exit code. This poses a significant risk to the integrity and availability of the host environment, particularly in containerized deployments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary OS commands on the host machine with the privileges of the OpenChamber application user. This could lead to full system compromise, data exfiltration, or deployment of further malicious payloads. The scope of impact is high, as the vulnerability resides in the default configuration for containerized environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided webserver detection rule to identify malicious POST requests targeting the /api/fs/exec endpoint.\u003c/li\u003e\n\u003cli\u003eAudit all OpenChamber deployments to ensure the UI_PASSWORD environment variable is explicitly configured to a strong, unique password.\u003c/li\u003e\n\u003cli\u003eUpdate OpenChamber to the latest patched version once available.\u003c/li\u003e\n\u003cli\u003eImplement egress network filtering to prevent the application container from initiating unauthorized external connections.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T17:25:56Z","date_published":"2026-08-06T15:25:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openchamber-rce/","summary":"OpenChamber 1.11.7 contains a critical unauthenticated RCE vulnerability in the /api/fs/exec endpoint due to improper command input validation and flawed authentication middleware.","title":"Unauthenticated Remote Code Execution in OpenChamber","url":"https://feed.craftedsignal.io/briefs/2026-08-openchamber-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-53975","version":"https://jsonfeed.org/version/1.1"}