CVE-2026-96795 HIGH
← Quay lại danh sáchinternal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 8.8 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Ngày công bố | 06:16 26/09/2026 |
| Ngày cập nhật | 23:32 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [security-advisories@github.com] https://github.com/horilla/horilla-hr/releases/tag/2.0.0
- [security-advisories@github.com] https://github.com/horilla/horilla-hr/security/advisories/GHSA-5g4v-4rv4-r26f
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/horilla/horilla-hr/security/advisories/GHSA-5g4v-4rv4-r26f
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 23:37 28/09/2026 | MODIFIED | modified_at | 2026-09-28T14:17:23Z | 2026-09-28T16:32:23Z |
| 23:37 28/09/2026 | MODIFIED | status | Received | Deferred |
| 21:17 28/09/2026 | CREATED | cve | HIGH |