CVE 9.3 CRITICAL

HRConvert2: Missing Sanitization enables Unauthenticated Remote Command Execution_CVE-2026-44666

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Description

HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its strip list. User input then reaches shell_exec(), where the shell interprets these characters and commands within filenames execute. This vulnerability is fixed in 3.3.8.

AI Analysis

Unauthenticated Remote Command Execution due to missing input sanitization

Basic Information

ID CVE-2026-44666
Source GitHub_M
Published May 14, 2026 at 20:32

Affected Product

Vendor zelon88
Product HRConvert2
Version < 3.3.8
Affected Versions zelon88 HRConvert2 < 3.3.8

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor zelon88
Product HRConvert2
Version < 3.3.8

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.