Back

HIGH

Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver

Published Jul 8, 2026

Description

Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames. Attackers can supply malicious filenames containing unescaped command substitution payloads through operations such as file upload, folder creation, rename, or deletion, which are interpolated into a double-quoted shell context and executed via proc_open() through /bin/sh -c before smbclient runs, resulting in arbitrary command execution on the underlying system.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Jul 8, 2026
Updated Jul 14, 2026
Reserved Jul 8, 2026

CISA Vulnrichment

Updated Jul 8, 2026

NVD

Status Deferred
Modified Jul 14, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Jul 8, 2026
Updated Jul 14, 2026

GitHub

No data