Critical severity9.9NVD Advisory· Published Jul 16, 2026· Updated Jul 18, 2026
CVE-2026-46512
CVE-2026-46512
Description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates.php output to extensions_custom.conf while only Dialplan/TemplateBase.php:38-42 sanitized contextName(), allowing a PERM_WRITE caller using confirm:true to inject arbitrary Asterisk directives such as System(), Set(SHELL(...)), Goto, or Macro. This issue is fixed in version 1.6.2.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.