Critical severity9.9NVD Advisory· Published Jul 4, 2024· Updated Jun 17, 2026
CVE-2024-39943
CVE-2024-39943
Description
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hfsnpm | < 0.52.10 | 0.52.10 |
Affected products
3- rejetto/HFSdescription
Patches
Vulnerability mechanics
References
5- github.com/rejetto/hfs/commit/305381bd36eee074fb238b64302a252668daad1dnvdPatchWEB
- github.com/rejetto/hfs/compare/v0.52.9...v0.52.10nvdPatchWEB
- github.com/advisories/GHSA-5f4x-hwv2-w9w2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-39943ghsaADVISORY
- www.rejetto.com/wiki/index.php/HFS:_Working_with_uploadsnvdProductWEB
News mentions
0No linked articles in our index yet.