CVE-2026-14863

🟡 Monitoruj

W FileRun występuje podatność na wstrzyknięcie poleceń, co umożliwia zdalne wykonanie kodu.

CVSS
8.8
EPSS
1.7%
Exploit
none
Vendor
Opis źródłowy (NVD)

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be evaluated as shell commands when ffmpeg, ImageMagick, vips, or stl-thumb processes the file during thumbnail generation.

rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.7%
Opublikowano (NVD)2026-08-11 21:17:25 UTC
Ostatnia modyfikacja (NVD)2026-09-16 13:42:42 UTC
Referencje