OS Command Injection in HFS - CVE-2024-39943
Published: July 8, 2024 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands on the underlying operating system.
The vulnerability exists due to command injection in the execSync command execution logic when executing shell commands. A remote user can send crafted input to execute arbitrary commands on the underlying operating system.