PatchSiren

FileRun CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FileRun CVE published 2026-09-10

CVE-2026-73694

CVE-2026-73694 is an OS command injection vulnerability in FileRun before version 2026.3.0. The vulnerability is caused by a no-op redefinition of escapeshellcmd() in CLI.php, which allows attacker-controlled input to reach an exec() sink unsanitized. This vulnerability can be exploited through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or t [truncated]