Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver
Published Jul 8, 2026
7.7
HIGHCVSS 4.0
EPSS 3.27%
Description
Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames. Attackers can supply malicious filenames containing unescaped command substitution payloads through operations such as file upload, folder creation, rename, or deletion, which are interpolated into a double-quoted shell context and executed via proc_open() through /bin/sh -c before smbclient runs, resulting in arbitrary command execution on the underlying system.
Affected products
-
Affected
- ≥ 0, < 3.0.1
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42340 Advisory
- https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361 patch
- https://github.com/horde/Vfs/pull/10 issue-tracking
- https://github.com/horde/Vfs/releases/tag/v3.0.1 release-notes
- https://www.vulncheck.com/advisories/horde-vfs-os-command-injection-via-horde-vfs-smb-driver third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42340 | Advisory | |
| https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361 | patch | |
| https://github.com/horde/Vfs/pull/10 | issue-tracking | |
| https://github.com/horde/Vfs/releases/tag/v3.0.1 | release-notes | |
| https://www.vulncheck.com/advisories/horde-vfs-os-command-injection-via-horde-vfs-smb-driver | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data