CRITICAL
An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload injection
Published Jan 5, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.76%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.