Arbitrary Code Execution in Horilla HR and CRM Software
CVE-2026-96795
8.8HIGH
What is CVE-2026-96795?
In versions prior to 2.0.0 of Horilla HR and CRM software, an authentication vulnerability exists in the HorillaListView.export_data method, located in horilla_views/generic/cbv/views.py. This flaw allows an authenticated user to manipulate the POST parameters. By crafting a specific input string that is interpreted as valid Python syntax, attackers can inject executable code. Such a vulnerability can result in the execution of arbitrary operating system commands, including critically privileged commands within the context of the application's running process, potentially gaining root access in Docker deployments. The issue has been addressed and resolved in version 2.0.0.
Affected Version(s)
horilla-hr < 2.0.0
