Arbitrary Code Injection in Frogman Headless PBX Control
CVE-2026-46512
9.9CRITICAL
What is CVE-2026-46512?
Frogman, a headless PBX control tool, allows remote manipulation through its MCP and HTTP API interfaces. Prior to version 1.6.2, a vulnerability existed where the fm_dialplan_apply method improperly handled template parameters. This oversight permitted attackers to inject arbitrary Asterisk directives by exploiting the insufficient sanitization of certain function parameters. As a result, malicious actors could potentially execute harmful commands on the system, heightening security risks. The issue has been addressed in version 1.6.2, which includes necessary protections against such exploits.
Affected Version(s)
frogman < 1.6.2
