Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53790

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

EPSS

Процентиль: 42%
0.00515
Низкий

8.1 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.1
ubuntu
24 дня назад

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

CVSS3: 8.1
redhat
24 дня назад

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

msrc
14 дней назад

rsync < 3.5.0 Command Injection via Multiple Code Paths

CVSS3: 8.1
debian
24 дня назад

rsync before 3.5.0contains multiple command and argument injection vul ...

suse-cvrf
17 дней назад

Security update for rsync

EPSS

Процентиль: 42%
0.00515
Низкий

8.1 High

CVSS3

Дефекты

CWE-78