OS Command Injection in ICEcoder Web Development Tool
CVE-2026-64837
8.7HIGH
What is CVE-2026-64837?
ICEcoder versions up to 8.1 are vulnerable to an OS command injection flaw due to the improper handling of filesystem paths in lib/properties.php. Authenticated users can exploit this issue by creating directories with specially crafted names containing shell metacharacters. This vulnerability allows attackers to invoke arbitrary commands as the web-server user by using the popen() function, potentially compromising the web application's security and integrity.
Affected Version(s)
ICEcoder 8.0 <= 8.1
