← Back to search

CVE-2026-71243

8.8 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw lies in the backmeup npm package, which directly concatenates user-provided values into shell commands, leading to potential command injection. This is significant because it allows an attacker to execute arbitrary commands, compromising the system.
Exploitability
Exploitation is relatively easy given that the package directly constructs shell commands from user inputs. An attacker needs access to the application or the ability to influence the input values.
Blast radius
If exploited, the impact could be severe, as it allows for full system compromise, potentially leading to data theft, service disruption, or further lateral movement within the network.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of backmeup, which addresses this vulnerability, or disable the feature that uses this package until a patch is available.
rceshell-injectionnpmcommand-injection

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = "mkdir -p " + path.join(info.destination, info.name) + "; " - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an argument array.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.