django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when an AS2 message is received or sent.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42168.json"
}{
"extracted_events": [
{
"introduced": "django-pyas2"
},
{
"fixed": "1.2.3"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}