vulnti.work

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained wi…

High CVSS 8.8
CVECVE-2026-64881
First seen2026-07-22 00:30 UTC
Disclosed2026-07-21 21:16 UTC
Last updated2026-07-22 00:30 UTC
Channel statusauto

Summary

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD