Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-97359: HFS2 allows attackers to run code via crafted upload filename
CVE-2026-97359 · published 16 days ago
Summary
Versions of HFS2 up to 2.4.0 let anyone upload a file with a specially crafted name that can cause the server to execute arbitrary commands. This can happen without any login, giving attackers control over the host system. Update to a newer version or apply the vendor's patch, and consider limiting or validating file upload names to protect your server.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rejetto | hfs2 | <= 2.4.0 |
Original advisory text
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Track software like this
Free during beta