OS Command Injection Vulnerability in FileRun by Interviews, Inc.
CVE-2026-73694

8.6HIGH

Key Information:

Vendor

Filerun

Status
Vendor
CVE Published:
10 September 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-73694?

FileRun prior to version 2026.3.0 is vulnerable to an OS command injection due to a vulnerable implementation of escapeshellcmd() in CLI.php. This flaw allows attackers to inject arbitrary commands through unsanitized input. Exploitation may occur via an interactive path through image_preview.php by providing a crafted args parameter, which requires superuser authentication to execute. Additionally, a persistent entry point exists through the storage of malicious payloads in thumbnails_ffmpeg_args or thumbnails_ffmpeg_ss variables, which can be triggered whenever any user attempts to generate a video thumbnail, posing a serious security risk.

Affected Version(s)

FileRun 0 < 2026.3.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
VulnCheck
.