CRITICAL
10.0 CVE-2026-97359 Published 24 Sept 2026
HFS2 Template Injection Vulnerability Allows Remote Code Execution
Worried this affects your website?
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler.
Unauthenticated attackers can achieve remote code execution by embedding malicious template syntax in a filename. A crafted filename containing a closing template quoting sequence followed by an exec macro bypasses the authorization check in the dispatcher and executes arbitrary commands on the underlying host system.
- Affected versions: HFS2 2.4.0 and earlier
- Attack vector: multipart upload handler via crafted filename
- Impact: unauthenticated remote code execution
Reference: CVE-2026-97359 on NVD
← Back to Security News