Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73974— linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

Quick assessment

Affected
Linuxfabrik monitoring-plugins
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linuxfabrik Python Libraries是Linuxfabrik组织开源的一系列Python开发库。 Linuxfabrik Python Libraries 6.1.0之前版本存在安全漏洞,该漏洞源于lib.lftest.test()将--test CSV参数的第一或第二个元素作为文件系统路径,并返回文件内容为模拟标准输出或标准错误且无路径限制,可能导致攻击者泄露root可读文件内容。

CVSS 5.5 · Medium EPSS 0.14% · P4

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 2

VendorProduct Version RangeStatus
Linuxfabrik lib < 6.0.1 affected
Linuxfabrik monitoring-plugins < 7.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73974

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
Source: CVE Program / CVE List V5
Vulnerability Description
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second element of a --test CSV argument as a filesystem path and returned the file contents as simulated standard output or standard error without path confinement. The hidden but production-accessible --test argument was accepted by sudo-authorized plugins, so an attacker controlling the nagios or icinga account could use check-plugins/deb-updates/deb-updates with its default QUERY=1 to disclose every line of a root-readable file. Approximately 22 other plugins exposed filtered content or a root file existence and readability oracle through the same helper, while check-plugins/network-bonding/network-bonding and check-plugins/openstack-swift-stat/openstack-swift-stat had direct read paths that bypassed the helper. The library fix confines fixture reads to the invoking plugin's unit-test directory and refuses unsafe anchors, and the plugin fix routes the two bypasses through that helper. These issues are fixed in linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
Linuxfabrik Python Libraries 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linuxfabrik Python Libraries是Linuxfabrik组织开源的一系列Python开发库。 Linuxfabrik Python Libraries 6.1.0之前版本存在安全漏洞,该漏洞源于lib.lftest.test()将--test CSV参数的第一或第二个元素作为文件系统路径,并返回文件内容为模拟标准输出或标准错误且无路径限制,可能导致攻击者泄露root可读文件内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linuxfabrik monitoring-plugins < 7.0.0 -
Linuxfabrik lib < 6.0.1 -

II. Public POCs for CVE-2026-73974

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73974

登录查看更多情报信息。

Patches & Fixes for CVE-2026-73974 (2)

Vendor Advisories for CVE-2026-73974 (1)

Vendor Pages for CVE-2026-73974 (1)

Same Patch Batch · Linuxfabrik · 2026-08-18 · 5 CVEs total

CVE-2026-55426 7.8 HIGH linuxfabrik-lib: Local privilege escalation using embedded command
CVE-2026-52817 7.0 HIGH Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalat
CVE-2026-73973 5.5 MEDIUM Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined --filename i
CVE-2026-53759 2.0 LOW linuxfabrik-lib: Insecure creation of SQLite databases

IV. Related Vulnerabilities

V. Comments for CVE-2026-73974

No comments yet


Leave a comment