You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Core] Kiteworks Core before 9.2.0 has an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Moderate
kw-fscheuer
published
GHSA-6j64-6fpp-9453Feb 26, 2026
Package
Kiteworks Core
Affected versions
<9.2.0
Patched versions
9.2.0
Description
Description
A vulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access.
Affected Versions
Kiteworks Core < 9.2.0
Remediation
Upgrade Kiteworks to version 9.2.0 or later.
Acknowledgments
We thank Icare and truff for reporting this security vulnerability through our bug bounty program on YesWeHack.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Learn more on MITRE.
Description
A vulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access.
Affected Versions
Remediation
Upgrade Kiteworks to version 9.2.0 or later.
Acknowledgments
We thank Icare and truff for reporting this security vulnerability through our bug bounty program on YesWeHack.