Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8pc-wmwr-cm52

Опубликовано: 29 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

EPSS

Процентиль: 3%
0.00017
Низкий

7.3 High

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
10 дней назад

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

EPSS

Процентиль: 3%
0.00017
Низкий

7.3 High

CVSS4

Дефекты

CWE-20