PT-2026-43401 · Prolix Oc · Lumiverse
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lumiverse versions prior to 0.9.7
Description
An issue exists where the application fails to properly validate the basename of a path when the
toSmbPath(fullPath) function throws an exception. In this fallback scenario, the basename is concatenated directly into an smbclient -c script. Because smbclient treats the semicolon (;) as a subcommand separator and the exclamation mark (!) as a local-shell escape, an attacker can provide a path with a malicious basename to achieve arbitrary command execution on the server.Recommendations
Update to version 0.9.7.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lumiverse