OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload
CVE-2026-25855

8.7HIGH

Key Information:

Vendor

Openbullet

Vendor
CVE Published:
8 June 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-25855?

OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.bat.ps1.sh) through the FileProxySource proxy loading feature. Attackers can upload malicious script files as proxy sources, causing the server to execute the scripts and return output as proxy lines, resulting in arbitrary command execution on the host as the process user.

Affected Version(s)

openbullet2 0.2.5 <= 0.3.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maksim Rogov
VulnCheck
.