Skip to content
Threat Feed

Tag

Os Command Injection

18 briefs RSS
high advisory

Remote Code Execution in GitList via OS Command Injection

GitList version 2.0.0 contains an OS command injection vulnerability in the getDefaultBranch function, allowing unauthenticated remote attackers to execute arbitrary system commands.

GitList web-application rce os-command-injection
1t 1c
critical advisory

IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)

A critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.

Aspera Faspex 5 remote-code-execution vulnerability os-command-injection web-application
1r 2t 1c
high threat

OS Command Injection Vulnerability in Pardus-Update (CVE-2026-16287)

A high-severity OS command injection vulnerability, tracked as CVE-2026-16287, has been identified in the TUBITAK BILGEM Software Technologies Research Institute's pardus-update software, affecting versions from 0.6.6 before 0.7.0, enabling attackers to execute arbitrary operating system commands due to improper neutralization of special elements.

exploited pardus-update os-command-injection vulnerability linux
1t 1c 1i
high advisory

CVE-2026-14448: Authenticated OS Command Injection in MB connect line and Helmholz Products

CVE-2026-14448 describes an authenticated OS command injection vulnerability in the system_certificates view of MB connect line's mbCONNECT24 and mymbCONNECT24 products, as well as Helmholz's myREX24V2 and myREX24V2.virtual products, all versions up to and including 2.20.0, allowing a high-privileged remote attacker to execute arbitrary commands leading to a total loss of confidentiality, availability, and integrity.

mbCONNECT24 +3 os-command-injection vulnerability rce industrial-control-system
1r 2t 1c
high threat

AVideo OS Command Injection Vulnerability (CVE-2026-63305)

AVideo versions through 29.0 contain an OS command injection vulnerability, CVE-2026-63305, in the ffmpeg.json.php endpoint where unescaped notifyCode and callback parameters can be exploited by attackers crafting encrypted payloads to execute arbitrary OS commands as the web-server user, potentially leading to full system compromise.

exploited AVideo os-command-injection web-application cve
1r 2t 1c 2i
high advisory

AVideo OS Command Injection Vulnerability (CVE-2026-63304)

AVideo versions up to and including 29.0 are vulnerable to an OS command injection (CVE-2026-63304) in the `listFFmpegProcesses()` function within `plugin/API/standAlone/functions.php`, allowing attackers to craft an encrypted `codeToExec` payload to bypass single-quote escaping and execute arbitrary operating system commands as the web-server user, leading to remote code execution.

AVideo os-command-injection rce web-vulnerability cve
1r 1t 1c 2i
critical advisory

Critical RCE Vulnerability in X-Rite MA-T6 Devices (CVE-2023-49900)

An unauthenticated remote attacker can achieve critical remote code execution in X-Rite MA-T6 devices running versions prior to v2.33 due to improper input sanitization in the `SetParameter` command, allowing for OS command injection via CVE-2023-49900.

MA-T6 rce command-injection os-command-injection firmware iot
2t 1c
high advisory

OS Command Injection Vulnerability in systeminformation Library via networkInterfaces()

A high-severity OS command injection vulnerability, CVE-2026-50289, exists in the `systeminformation` Node.js library on Linux systems, allowing an attacker who can manipulate `interfaces(5)` configuration files to execute arbitrary commands with the privileges of the calling Node.js process by injecting shell metacharacters into `source` directive paths, which are then unsafely interpolated into an `execSync()` command within the `networkInterfaces()` function.

systeminformation command-injection os-command-injection nodejs linux exploitation
1r 1t 1i
critical advisory

Unauthenticated OS Command Injection in Vitec Flamingo

Vitec Flamingo version 4.12.2 contains an unauthenticated OS command injection vulnerability (CVE-2026-60121) in the `admin/ajax/ping.php` endpoint, allowing remote attackers to execute arbitrary commands with root privileges via a double-evaluation flaw in shell argument handling through the `host` POST parameter.

PoC Flamingo 4.12.2 os-command-injection rce web-application linux
1r 2t 2c updated
high advisory

Laravel-Backup-Restore OS Command Injection (CVE-2026-53932)

A critical OS command injection vulnerability, tracked as CVE-2026-53932, exists in the wnx/laravel-backup-restore package (versions <= 1.9.3), allowing an attacker to execute arbitrary shell commands on the hosting system by crafting a malicious backup archive with shell metacharacters in a database dump filename, leading to application compromise, data tampering, and potential lateral movement.

laravel-backup-restore <= 1.9.3 os-command-injection laravel php vulnerability cve-2026-53932
2r 2t
high advisory

CVE-2026-60102: Horde VFS OS Command Injection Vulnerability

CVE-2026-60102 describes an OS command injection vulnerability in the Horde Virtual File System (VFS) API before version 3.0.1, specifically within the Horde_Vfs_Smb driver, which allows authenticated attackers to inject arbitrary shell commands via user-controlled filenames during file operations, leading to arbitrary command execution on the underlying system.

Horde Virtual File System os-command-injection rce webserver horde cve
1r 1t 1c
critical threat

Critical OS Command Injection in 9Router (CVE-2026-59800)

A critical OS command injection vulnerability (CVE-2026-59800) affects 9Router versions prior to 0.4.44, allowing unauthenticated remote attackers to execute arbitrary OS commands as root via a crafted POST request to the /api/tunnel/tailscale-install endpoint, leading to full system compromise with active exploitation observed.

exploited 9Router < 0.4.44 os-command-injection rce web-vulnerability network-appliance linux
1r 2t 1c
high threat

Dolibarr ERP/CRM OS Command Injection (CVE-2023-30253) Exploit Publicly Available

A public exploit is available for an OS Command Injection vulnerability in Dolibarr ERP/CRM versions prior to 17.0.1 (CVE-2023-30253), which allows authenticated users to inject PHP code via the Website/CMS module to obtain a reverse shell as the www-data user.

Dolibarr ERP/CRM < 17.0.1 cve-2023-30253 os command injection rce web application
2r 1t 1c 2i
critical advisory

SambaBox OS Command Injection Vulnerability (CVE-2026-3120)

SambaBox versions 5.1 to before 5.3 are vulnerable to OS command injection via improper control of code generation (CVE-2026-3120), potentially allowing attackers with high privileges to execute arbitrary commands on the underlying system.

SambaBox code-injection os-command-injection cve-2026-3120
2r 1t 1c
high advisory

PraisonAI OS Command Injection Vulnerability (CVE-2026-34937)

PraisonAI versions prior to 1.5.90 are vulnerable to OS Command Injection (CVE-2026-34937) due to insufficient escaping in the run_python() function, allowing arbitrary OS command execution via shell interpolation.

cve-2026-34937 os command injection praisonai
2r 1t 1c
critical advisory

Ruckus Unleashed Authenticated Remote Code Execution via CVE-2023-7338

CVE-2023-7338 is a remote code execution vulnerability affecting Ruckus Unleashed when gateway mode is enabled, allowing authenticated remote attackers to execute arbitrary code by sending specially crafted requests through the web-based management interface.

CVE-2023-7338 ruckus rce os command injection
2r 3t
critical advisory

Chamilo LMS OS Command Injection Vulnerability (CVE-2026-35196)

Chamilo LMS versions prior to 2.0.0-RC.3 are vulnerable to OS Command Injection via the _cid session variable in the export_all_certificates action, potentially leading to arbitrary command execution.

PoC cve-2026-35196 os command injection chamilo lms web application
2r 1t 1c updated
critical advisory

Pardus OS My Computer OS Command Injection Vulnerability (CVE-2026-6849)

CVE-2026-6849 is an OS Command Injection vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer versions <=0.7.5 before 0.8.0, allowing an attacker to execute arbitrary OS commands due to improper neutralization of special elements.

Pardus OS My Computer cve-2026-6849 os command injection pardus os
1r 1t 1c