PT-2026-60850 · Undefined · Undefined

CVE-2026-42168

·

Published

2026-07-17

·

Updated

2026-07-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd receive and cmd send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when an AS2 message is received or sent.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42168

Affected Products

Undefined