CVE-2026-14863
🟡 Monitoruj
W FileRun występuje podatność na wstrzyknięcie poleceń, co umożliwia zdalne wykonanie kodu.
CVSS
8.8
EPSS
1.7%
Exploit
none
Vendor
Opis źródłowy (NVD)
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be evaluated as shell commands when ffmpeg, ImageMagick, vips, or stl-thumb processes the file during thumbnail generation.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.7% |
| Opublikowano (NVD) | 2026-08-11 21:17:25 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 13:42:42 UTC |
Referencje
- https://filerun.com/ ([email protected])
- https://filerun.com/index.php/changelog?v=2026.2.1 ([email protected])
- https://www.vulncheck.com/advisories/filerun-rce-via-thumbnail-generation-command-injection ([email protected])
- https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce ([email protected])