Source: php-horde-vfs
Version: 2.4.2-1
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://github.com/horde/Vfs/pull/10
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for php-horde-vfs.

CVE-2026-60102[0]:
| Horde Virtual File System (VFS) API before 3.0.1 contains an OS
| command injection vulnerability in the Horde_Vfs_Smb driver where
| the _escapeShellCommand() method fails to sanitize command
| substitution sequences, allowing authenticated attackers to inject
| arbitrary shell commands through user-controlled filenames.
| Attackers can supply malicious filenames containing unescaped
| command substitution payloads through operations such as file
| upload, folder creation, rename, or deletion, which are interpolated
| into a double-quoted shell context and executed via proc_open()
| through /bin/sh -c before smbclient runs, resulting in arbitrary
| command execution on the underlying system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-60102
    https://www.cve.org/CVERecord?id=CVE-2026-60102
[1] https://github.com/horde/Vfs/pull/10
[2] https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361

Regards,
Salvatore

Reply via email to