CVE-2026-63725: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in nuxsmin sysPass
sysPass version 3.0.0 contains an OS command injection vulnerability in its FileBackupService::doBackupFiles() function. The vulnerability arises because the backup directory path is concatenated directly into a shell command without proper escaping or validation. An attacker with administrator privileges or access to an admin API token can exploit this to execute arbitrary OS commands as the web server user, potentially exposing all stored credentials and enabling further system compromise.
AI Analysis
Technical Summary
In sysPass 3.0.0, the FileBackupService::doBackupFiles() method constructs a tar command by concatenating the backup directory path directly into the shell command string without using escapeshellarg() or validating the path. This path is configurable via the admin API or UI and stored in the database. An attacker with admin access can inject shell metacharacters into this path, causing arbitrary OS command execution under the web server user context. Given sysPass's role as a password manager, this can lead to disclosure of the master password, decryption keys, and all stored credentials, as well as enabling lateral movement and persistent compromise.
Potential Impact
Successful exploitation allows an attacker with admin privileges to execute arbitrary OS commands as the web server user (typically www-data or apache). This can lead to full disclosure of the password vault, including the master password and encryption keys, enabling decryption of all stored credentials. The attacker can also pivot to internal systems using these credentials and install persistent backdoors on the host running sysPass.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict administrative access to trusted users only and monitor for suspicious activity. Avoid using untrusted input in backup path configuration. Consider manual review or temporary disabling of backup operations if feasible.
CVE-2026-63725: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in nuxsmin sysPass
Description
sysPass version 3.0.0 contains an OS command injection vulnerability in its FileBackupService::doBackupFiles() function. The vulnerability arises because the backup directory path is concatenated directly into a shell command without proper escaping or validation. An attacker with administrator privileges or access to an admin API token can exploit this to execute arbitrary OS commands as the web server user, potentially exposing all stored credentials and enabling further system compromise.
CVSS v3.1
Score 7.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In sysPass 3.0.0, the FileBackupService::doBackupFiles() method constructs a tar command by concatenating the backup directory path directly into the shell command string without using escapeshellarg() or validating the path. This path is configurable via the admin API or UI and stored in the database. An attacker with admin access can inject shell metacharacters into this path, causing arbitrary OS command execution under the web server user context. Given sysPass's role as a password manager, this can lead to disclosure of the master password, decryption keys, and all stored credentials, as well as enabling lateral movement and persistent compromise.
Potential Impact
Successful exploitation allows an attacker with admin privileges to execute arbitrary OS commands as the web server user (typically www-data or apache). This can lead to full disclosure of the password vault, including the master password and encryption keys, enabling decryption of all stored credentials. The attacker can also pivot to internal systems using these credentials and install persistent backdoors on the host running sysPass.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict administrative access to trusted users only and monitor for suspicious activity. Avoid using untrusted input in backup path configuration. Consider manual review or temporary disabling of backup operations if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-17T21:21:58.625Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a750707bf8831d5395f5ac7
Added to database: 08/06/2026, 22:13:27 UTC
Last enriched: 08/06/2026, 22:56:18 UTC
Last updated: 08/06/2026, 23:21:03 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.