VYPR
Critical severity9.1NVD Advisory· Published Aug 27, 2026

CVE-2026-57499

CVE-2026-57499

Description

Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The ip_address parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. This is fixed in 2.2.2 - 1103.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Liman/Coreinferred2 versions
    <2.2.2-1103+ 1 more
    • (no CPE)range: <2.2.2-1103
    • (no CPE)range: >=2.2.2 - 1103
  • Liman/Limanllm-fuzzy
    Range: <2.2.2 - 1103

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.