CVE-2026-64837

Source
https://cve.org/CVERecord?id=CVE-2026-64837
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64837.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64837
Published
2026-09-10T13:51:06Z
Modified
2026-09-12T03:46:28Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
ICEcoder through 8.1 OS Command Injection via lib/properties.php
Details

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64837.json"
}
References

Affected packages

Git / github.com/icecoder/icecoder

Affected ranges

Type
GIT
Repo
https://github.com/icecoder/icecoder
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.0"
        },
        {
            "last_affected": "8.1"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "8.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

8.*
8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64837.json"