{"id":"CVE-2026-71243","published":"2026-08-05T11:16:27.247","lastModified":"2026-08-10T12:17:26.857","description":"The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an argument array.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://github.com/adaltas/node-backmeup","tags":[]}],"exploitRefs":[{"url":"https://github.com/adaltas/node-backmeup","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw lies in the backmeup npm package, which directly concatenates user-provided values into shell commands, leading to potential command injection. This is significant because it allows an attacker to execute arbitrary commands, compromising the system.","exploitability":"Exploitation is relatively easy given that the package directly constructs shell commands from user inputs. An attacker needs access to the application or the ability to influence the input values.","blast_radius":"If exploited, the impact could be severe, as it allows for full system compromise, potentially leading to data theft, service disruption, or further lateral movement within the network.","remediation":"Upgrade to the latest version of backmeup, which addresses this vulnerability, or disable the feature that uses this package until a patch is available.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","shell-injection","npm","command-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:19:09.092Z"}}