<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>HFS - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/hfs/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 14:46:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/hfs/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in HFS2 via Template Injection</title><link>https://feed.craftedsignal.io/briefs/2026-09-hfs2-template-injection/</link><pubDate>Thu, 24 Sep 2026 14:46:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-hfs2-template-injection/</guid><description>HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution.</description><content:encoded><![CDATA[<p>HFS2 version 2.4.0 and earlier contains a template injection vulnerability within its multipart upload handler. An unauthenticated attacker can exploit this flaw by crafting a filename containing a malicious template quoting sequence followed by an exec macro. This vulnerability allows the attacker to bypass authorization checks within the application's dispatcher mechanism, resulting in remote code execution (RCE) on the underlying host system. Given the nature of the flaw, successful exploitation leads to full compromise of the server. Organizations running affected versions of HFS2 are at high risk and should prioritize remediation or apply necessary access controls to restrict access to the upload functionality until a patch is applied.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary remote code execution on the host system, granting the attacker the permissions of the user running the HFS2 application. This vulnerability poses a severe threat to any environment hosting HFS2, potentially leading to total system takeover, data exfiltration, and further lateral movement within the network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of all HFS2 installations to a patched version beyond 2.4.0. If immediate patching is not possible, restrict access to the multipart upload endpoint at the web application firewall or reverse proxy layer until remediation is complete.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>