{"id":"GHSA-73v2-rxqp-7q4f","summary":"aliyundrive-webdav vulnerable to Command Injection","details":"An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component.","aliases":["CVE-2024-29640","PYSEC-2026-1114"],"modified":"2026-07-07T17:56:45.506618367Z","published":"2024-03-29T18:30:42Z","database_specific":{"nvd_published_at":"2024-03-29T17:15:12Z","cwe_ids":["CWE-77"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-03-29T20:14:34Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29640"},{"type":"WEB","url":"https://github.com/lakemoon602/vuln/blob/main/detail.md"},{"type":"PACKAGE","url":"https://github.com/messense/aliyundrive-webdav"},{"type":"WEB","url":"https://github.com/messense/aliyundrive-webdav/blob/main/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.lua"},{"type":"WEB","url":"http://aliyundrive-webdav.com"}],"affected":[{"package":{"name":"aliyundrive-webdav","ecosystem":"crates.io","purl":"pkg:cargo/aliyundrive-webdav"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json"}},{"package":{"name":"aliyundrive-webdav","ecosystem":"PyPI","purl":"pkg:pypi/aliyundrive-webdav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.3.3"}]}],"versions":["0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.24","0.1.25","0.1.26","0.1.27","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.1","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.5.5","1.0.0","1.1.0","1.1.1","1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.10.5","1.10.6","1.10.7","1.11.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.3.0","1.3.1","1.3.2","1.3.3","1.4.0","1.5.0","1.5.1","1.6.0","1.6.1","1.6.2","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","1.9.0","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.2.0","2.2.1","2.2.2","2.3.0","2.3.1","2.3.2","2.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json"}}],"schema_version":"1.9.0"}