VYPR

Uac

by Tclahr

Source repositories

CVEs (4)

  • CVE-2026-41451HigAug 21, 2026
    risk 0.44cvss 7.8epss 0.01

    UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping…

  • CVE-2026-41450HigAug 21, 2026
    risk 0.44cvss 7.8epss 0.01

    UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with…

  • CVE-2026-41449HigAug 21, 2026
    risk 0.44cvss 7.8epss 0.01

    UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or…

  • CVE-2026-40032HigApr 8, 2026
    risk 0.44cvss 7.8epss 0.01

    UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution pipeline where the _run_command() function passes constructed command strings directly to eval without proper sanitization.…