Skip to main content
HIGH

CVE-2026-73694

CVSS v3

7.2

HIGH

EPSS Score

1.8 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or through a persistent path by storing malicious payloads in thumbnails_ffmpeg_args or thumbnails_ffmpeg_ss t

Technical details

CVSS v3 Vector
3.1
Published
2026-09-10
Last Modified
2026-09-11

Frequently asked questions

What is CVE-2026-73694?

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or through a persistent path by storing malicious payloads in thumbnails_ffmpeg_args or thumbnails_ffmpeg_ss t

Is CVE-2026-73694 actively exploited?

Active exploitation of CVE-2026-73694 has not been confirmed. The EPSS score is 1.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-73694?

CVE-2026-73694 has a CVSS v3 base score of 7.2 (HIGH severity), with vector string 3.1.

Is CVE-2026-73694 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key