Skip to main content
CRITICAL

CVE-2026-88393

WookTeam Remote Code Execution via Base64-Decoded Eval Injection in Task Export API

CVSS v3

9.8

CRITICAL

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published
2026-10-05
Last Modified
2026-10-06

Frequently asked questions

What is CVE-2026-88393?

WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.

Is CVE-2026-88393 actively exploited?

Active exploitation of CVE-2026-88393 has not been confirmed.

What is the CVSS score for CVE-2026-88393?

CVE-2026-88393 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Is CVE-2026-88393 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key