CVE-2026-40030

parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is passed unsanitized into an os.popen() shell command with ls, allowing arbitrary command injection via crafted volume path arguments containing shell metacharacters. An attacker can provide a crafted volume path via the -v flag that injects arbitrary commands during volume content enumeration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:khyrenz:parseusbs:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-08 22:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-40030

Mitre link : CVE-2026-40030

CVE.ORG link : CVE-2026-40030


JSON object : View

Products Affected

khyrenz

  • parseusbs
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')