CVE-2026-73693
FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
Description
FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file containing command substitution syntax such as backticks, semicolons, or $() sequences in the filename, then trigger the PhotoProofSheet endpoint to execute arbitrary commands as the web-server user due to missing escapeshellarg() sanitization in the ImageMagick montage command construction.
In plain language
AI Act nowFileRun before 2026.3.0 lets a logged-in user who can upload files take control of the server, so small businesses using it should act quickly.
Authenticated OS command injection in FileRun’s PhotoProofSheet handler lets upload-permitted users execute arbitrary commands through specially crafted filenames.
What to do now
- Check whether you run FileRun and confirm its installed version is earlier than 2026.3.0.
- Upgrade FileRun to version 2026.3.0.
- Until upgraded, restrict upload permissions to trusted staff and limit access to the photo proof sheet feature.
- Review server activity for unexpected commands or files created by the web service.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-73693 and every CVE in our database. Create a free account — no credit card required.
Create Free Account