A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Upload File" action constructs a shell command from the ftp_file parameter and executes it using os.system() without sanitization or escaping.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Upload File" action constructs a shell command from the ftp_file parameter and executes it using os.system() without sanitization or escaping. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-09-09T00:00:00.000Z
Updated: 2025-09-10T14:06:40.486Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57633

Updated: 2025-09-10T14:05:47.586Z

Status : Awaiting Analysis
Published: 2025-09-09T21:15:38.223
Modified: 2025-09-11T17:14:25.240
Link: CVE-2025-57633

No data.