VYPR

Horde_Vfs_Smb

by Horde (software)

Source repositories

CVEs (1)

  • CVE-2026-60102HigJul 8, 2026
    risk 0.50cvss 8.8epss 0.02

    Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell…