{"id":"CVE-2026-100714","published":"2026-09-26T14:16:57.240","lastModified":"2026-09-26T23:16:33.297","description":"Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only blacklists shell metacharacters such as ; | & > < \\ $ ~ ?, spaces and quotes survive and the value is word-split into additional acme.sh arguments. An administrator, or any actor able to write settings (for example through the settings-import API), can therefore inject acme.sh options such as --renew-hook, --pre-hook or --post-hook to obtain arbitrary command execution as root at the next Let's Encrypt cron run, or use --config-home/--cert-home for arbitrary file writes. Versions up to and including 2.3.10 are affected; the issue is fixed in 2.3.12.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-88"],"vendors":[],"products":[],"references":[{"url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-3w4g-cmpj-rj42","tags":[]},{"url":"https://www.vulncheck.com/advisories/froxlor-before-2.3.12-command-injection-via-letsencryptchallengepath","tags":[]}],"exploitRefs":[{"url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-3w4g-cmpj-rj42","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to inject acme.sh options, leading to arbitrary command execution as root during Let's Encrypt certificate renewals.","exploitability":"Exploitation is relatively easy if an attacker can write settings, such as through the settings-import API.","blast_radius":"If exploited, attackers could gain full control over the system, leading to severe data breaches or system compromise.","remediation":"Upgrade to Froxlor version 2.3.12 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","cve","letsencrypt","arbitrary-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:53:38.091Z"}}