← Back
Web Application
CVE-2026-73680 high CVSS 8.8

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...

Summary

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...

AI summary openai / gpt-4o

Cockpit CMSのバージョン2.14.0およびそれ以前に、FFmpeg統合におけるコマンドインジェクションの脆弱性があります。この脆弱性により、認証されたユーザーが資産/アップロード権限のみで任意のコマンドを実行できます。これにより、任意のシェルメタキャラクターが使用されたファイル名を持つビデオファイルをアップロードすることで、悪意のあるコマンド実行が可能です。
❓ What is the problem
Cockpit CMSにおけるFFmpeg統合でのコマンドインジェクション脆弱性です。
📍 Affected scope
Cockpit CMS バージョン2.14.0およびそれ以前。
🔥 Severity
認証されたユーザーが任意のコマンドを実行できるため、高度に危険です。
🔧 How to fix
ユーザーからの入力を適切にサニタイズするか、脆弱性が修正された新しいバージョンへアップデートしてください。
🛡️ Workaround
情報なし
🔍 Detection
Cockpit CMSのバージョンを確認し、脆弱性があるかどうかを判断します。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →