Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or through a persistent path by storing malicious payloads in thumbnails_ffmpeg_args or thumbnails_ffmpeg_ss that execute when any user triggers video thumbnail generation. | |
| Title | FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-10T16:33:00.306Z
Reserved: 2026-08-13T15:15:54.513Z
Link: CVE-2026-73694
No data.
Status : Received
Published: 2026-09-10T17:17:05.813
Modified: 2026-09-10T17:17:05.813
Link: CVE-2026-73694
No data.
OpenCVE Enrichment
Updated: 2026-09-10T18:15:06Z