{"id":"PYSEC-2026-1114","summary":"aliyundrive-webdav vulnerable to Command Injection","details":"An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component.","aliases":["CVE-2024-29640","GHSA-73v2-rxqp-7q4f"],"modified":"2026-07-07T17:46:11.024043778Z","published":"2026-07-07T11:45:37.035521Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29640"},{"type":"WEB","url":"https://github.com/lakemoon602/vuln/blob/main/detail.md"},{"type":"PACKAGE","url":"https://github.com/messense/aliyundrive-webdav"},{"type":"WEB","url":"https://github.com/messense/aliyundrive-webdav/blob/main/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.lua"},{"type":"WEB","url":"http://aliyundrive-webdav.com"},{"type":"PACKAGE","url":"https://pypi.org/project/aliyundrive-webdav"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-73v2-rxqp-7q4f"}],"affected":[{"package":{"name":"aliyundrive-webdav","ecosystem":"PyPI","purl":"pkg:pypi/aliyundrive-webdav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.3.3"}]}],"versions":["0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.24","0.1.25","0.1.26","0.1.27","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.1","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.5.5","1.0.0","1.1.0","1.1.1","1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.10.5","1.10.6","1.10.7","1.11.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.3.0","1.3.1","1.3.2","1.3.3","1.4.0","1.5.0","1.5.1","1.6.0","1.6.1","1.6.2","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","1.9.0","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.2.0","2.2.1","2.2.2","2.3.0","2.3.1","2.3.2","2.3.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/aliyundrive-webdav/PYSEC-2026-1114.yaml"}}],"schema_version":"1.7.5"}