GHSA-j2g9-rprv-hrhc

Suggest an improvement
Source
https://github.com/advisories/GHSA-j2g9-rprv-hrhc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-j2g9-rprv-hrhc/GHSA-j2g9-rprv-hrhc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j2g9-rprv-hrhc
Aliases
  • CVE-2026-31019
Published
2026-04-21T15:32:22Z
Modified
2026-05-05T16:07:42.449812Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Dolibarr user with permission to edit PHP content can bypass filtering to restrict dangerous PHP functions
Details

In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code execution with the ability to execute arbitrary operating system commands on the server.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-29T20:40:34Z",
    "nvd_published_at": "2026-04-21T15:16:36Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / dolibarr/dolibarr

Package

Name
dolibarr/dolibarr
Purl
pkg:composer/dolibarr/dolibarr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
22.0.4

Affected versions

3.*
3.6.0-beta
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0-beta
3.8.0
3.8.1
3.8.2
3.8.3
3.8.4
3.9.0-rc
3.9.0-rc2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
4.*
4.0.0-beta
4.0.0-rc
4.0.0-rc2
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
5.*
5.0.0-beta
5.0.0-rc1
5.0.0-rc2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
6.*
6.0.0-beta
6.0.0-rc
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
9.*
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
10.*
10.0.0
10.0.1
10.0.2
10.0.3
10.0.4
10.0.5
10.0.6
10.0.7
11.*
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
12.*
12.0.0
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
13.*
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
14.*
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
15.*
15.0.0
15.0.1
15.0.2
15.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-j2g9-rprv-hrhc/GHSA-j2g9-rprv-hrhc.json"