GHSA-x2v3-fq4f-vvjjCriticalCVSS 9.9

A filename supplied during file upload is not properly sanitized before being used in system...

Published
July 21, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

🔗 References (3)