{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/filerun/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14863"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FileRun (\u003c= 2026.2.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","command-injection","file-upload"],"_cs_type":"advisory","_cs_vendors":["FileRun"],"content_html":"\u003cp\u003eFileRun versions up to and including 2026.2.0 contain an OS command injection vulnerability located within the application's thumbnail generation system. The vulnerability exists because the application passes file names containing shell command substitution sequences directly to system-level execution functions without adequate sanitization or escaping via \u003ccode\u003eescapeshellarg()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAn authenticated attacker can exploit this by uploading a specially crafted file with a malicious filename (e.g., using syntax like \u003ccode\u003e$(PAYLOAD).mp4\u003c/code\u003e). When the system attempts to generate a thumbnail for the uploaded file using back-end utilities such as ffmpeg, ImageMagick, vips, or stl-thumb, the shell interprets the embedded payload. This allows for remote code execution on the host server under the privileges of the web application user. This flaw is particularly significant for environments where file uploads are permitted for authenticated users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to achieve arbitrary remote code execution on the server. This can lead to full system compromise, data exfiltration, or lateral movement within the environment. All deployments of FileRun version 2026.2.0 and earlier are susceptible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FileRun to the latest version as soon as a patch is available.\u003c/li\u003e\n\u003cli\u003eIdentify and audit user upload directories for files containing shell metacharacters or suspicious extensions.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for requests to thumbnail generation or upload endpoints that exhibit unusual query parameters or filename patterns.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to exploit CVE-2026-14863 by identifying shell injection patterns in the process lineage of thumbnail generation utilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T21:52:34Z","date_published":"2026-08-11T21:52:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-filerun-rce/","summary":"FileRun versions up to 2026.2.0 contain a command injection vulnerability in the thumbnail generation component allowing authenticated attackers to execute arbitrary code.","title":"OS Command Injection in FileRun Thumbnail Generation","url":"https://feed.craftedsignal.io/briefs/2026-08-filerun-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - FileRun","version":"https://jsonfeed.org/version/1.1"}