Home

Description

Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names

PUBLISHED Reserved 2026-03-31 | Published 2026-04-08 | Updated 2026-04-08 | Assigner GitLab




HIGH: 8.2CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

3.1.0 (semver) before 4.0.0
affected

Credits

https://gitlab.com/lassi-3 finder

References

gitlab.com/...1.0/coolercontrold/src/alerts.rs?ref_type=tags

gitlab.com/coolercontrol/coolercontrol/-/releases/4.0.0

cve.org (CVE-2026-5208)

nvd.nist.gov (CVE-2026-5208)

Download JSON