🟢 Authenticated Backup GraphQL Restore Filename Command Injection

Summary

The Backup module accepts user-controlled filenames that may contain malicious characters, potentially resulting in command injection as the asterisk user.

Authentication with a known username is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-65g4-v227-g8m3

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: