Bug#1143051: php-horde-vfs: CVE-2026-60102

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178538575378.1134897.17707792806780273206.reportbug__6257.23189893819$1785385876$gmane$org@eldamar.lan>
Source: php-horde-vfs
Version: 2.4.2-1
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://github.com/horde/Vfs/pull/10
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for php-horde-vfs.

CVE-2026-60102[0]:
| Horde Virtual File System (VFS) API before 3.0.1 contains an OS
| command injection vulnerability in the Horde_Vfs_Smb driver where
| the _escapeShellCommand() method fails to sanitize command
| substitution sequences, allowing authenticated attackers to inject
| arbitrary shell commands through user-controlled filenames.
| Attackers can supply malicious filenames containing unescaped
| command substitution payloads through operations such as file
| upload, folder creation, rename, or deletion, which are interpolated
| into a double-quoted shell context and executed via proc_open()
| through /bin/sh -c before smbclient runs, resulting in arbitrary
| command execution on the underlying system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-60102
    https://www.cve.org/CVERecord?id=CVE-2026-60102
[1] https://github.com/horde/Vfs/pull/10
[2] https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.