Vulnerability Intelligence Report
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
CVE-2026-97359
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-1336 ↗Improper Neutralization of Special Elements Used in a Template Engine
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| rejetto | hfs2 | 2.0.0 <= 2.4.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-09-24T13:24:49 |
| Published | 2026-09-24T13:28:18 |
| Patch Date | 2026-09-24 |
| Last Updated | 2026-09-24T13:28:18 |
Community Chatter & Buzz