PT-2026-25970 · Xiaoheifs · Xiaoheifs

Yinglongkaqi

·

Publicado

2026-03-18

·

Atualizado

2026-03-19

·

CVE-2026-28673

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xiaoheiFS versions up to and including 0.3.15
Description xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. The standard plugin system allows administrators to upload a ZIP file containing a binary and a manifest.json. The server trusts the binaries field within the manifest.json file and executes the specified file without validating its contents or behavior. This can lead to Remote Code Execution (RCE). The manifest.json file contains the binaries field, which specifies the file to be executed. Version 0.4.0 resolves this issue.
Recommendations Versions prior to 0.4.0 should be updated to version 0.4.0 or later.

Exploit

Correção

RCE

Unrestricted File Upload

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28673

Produtos afetados

Xiaoheifs