Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73694— FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition

Quick assessment

Affected
FileRun FileRun
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FileRun 2026.3.0 之前的版本存在操作系统命令注入漏洞。该漏洞由 CLI.php 中对 的空操作(no-op)重定义引发,导致 shell 元字符的转义被移除,使得攻击者可控的输入未经净化便直接传递至 调用点(sink)。攻击者可通过以下两种路径利用该漏洞: 1. 交互式路径:通过 中精心构造的 参数进行利用,此路径需要超级用户身份验证。 2. 持久化路径:将恶意载荷存储在 或 字段中,当任意用户触发视频缩略图生成时,这些载荷会被执行。

CVSS 7.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73694

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition
Source: CVE Program / CVE List V5
Vulnerability Description
FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or through a persistent path by storing malicious payloads in thumbnails_ffmpeg_args or thumbnails_ffmpeg_ss that execute when any user triggers video thumbnail generation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FileRun FileRun 0 ~ 2026.3.0 -

II. Public POCs for CVE-2026-73694

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73694

登录查看更多情报信息。

Vendor Advisories for CVE-2026-73694 (1)

Security Blog Posts for CVE-2026-73694 (1)

Same Patch Batch · FileRun · 2026-09-10 · 4 CVEs total

CVE-2026-73693 8.8 HIGH FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
CVE-2026-73698 7.2 HIGH FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
CVE-2026-73699 7.2 HIGH FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

IV. Related Vulnerabilities

V. Comments for CVE-2026-73694

No comments yet


Leave a comment