Home
MEDIUM: 6.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:PDefault status
affected
7.1.4208
unaffected
7.2.5090
unaffected
8.0.0
unaffected
Description
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
7.1.4208
7.2.5090
8.0.0
References
github.com/...Disclosures/blob/master/2025/MNDT-2025-0004.md
cloud.google.com/...emote-code-execution-aviatrix-controller