{"id":"CVE-2026-67243","published":"2026-08-04T08:16:35.240","lastModified":"2026-08-04T14:16:32.310","description":"freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://github.com/refirio/freo2/commits/main/","tags":[]},{"url":"https://jvn.jp/en/jp/JVN52865575/","tags":[]}],"exploitRefs":[{"url":"https://github.com/refirio/freo2/commits/main/","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows an admin to upload and execute arbitrary files, leading to remote code execution.","exploitability":"Exploitation requires administrative privileges but is straightforward once obtained.","blast_radius":"If exploited, it could lead to full control over the affected system, including data theft or destruction.","remediation":"Update to the latest version of freo2 that addresses this vulnerability.","tags":["rce","admin-privilege","upload-vuln"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:01:01.441Z"}}