← Back to CVE List
Vulnerability Intelligence Report
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection

CVE-2026-97359

x_open-sourceunsupported-when-assigned

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-1336 ↗Improper Neutralization of Special Elements Used in a Template Engine

Affected Products & Versions

Vendor Product Affected Versions
rejetto hfs2 2.0.0 <= 2.4.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-09-24T13:24:49
Published2026-09-24T13:28:18
Patch Date2026-09-24
Last Updated2026-09-24T13:28:18

LINK COPIED TO CLIPBOARD