OS Command Injection Vulnerability in FileRun by Interviews, Inc.
CVE-2026-73694
Key Information:
Badges
What is CVE-2026-73694?
FileRun prior to version 2026.3.0 is vulnerable to an OS command injection due to a vulnerable implementation of escapeshellcmd() in CLI.php. This flaw allows attackers to inject arbitrary commands through unsanitized input. Exploitation may occur via an interactive path through image_preview.php by providing a crafted args parameter, which requires superuser authentication to execute. Additionally, a persistent entry point exists through the storage of malicious payloads in thumbnails_ffmpeg_args or thumbnails_ffmpeg_ss variables, which can be triggered whenever any user attempts to generate a video thumbnail, posing a serious security risk.
Affected Version(s)
FileRun 0 < 2026.3.0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
