Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-41010

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-78 Neutralización incorrecta de elementos especiales usados en un comando de sistema operativo (Inyección de comando de sistema operativo)
Fecha de publicación:
04/06/2026
Última modificación:
04/06/2026

Descripción

*** Pendiente de traducción *** ReleaseJob#unpack builds job_dir = File.join(@release_dir, &amp;#39;jobs&amp;#39;, name) and job_tgz = File.join(@release_dir, &amp;#39;jobs&amp;#39;, "#{name}.tgz") where name returns @job_meta[&amp;#39;name&amp;#39;], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into a shell string: Bosh::Common::Exec.sh("tar -C #{job_dir} -xf #{job_tgz} 2&gt;&amp;1", :on_error =&gt; :return). Bosh::Common::Exec.sh executes via %x{#{command}} (bosh-common/lib/bosh/common/exec.rb:53), i.e. /bin/sh -c, so any shell metacharacters in name are interpreted. FileUtils.mkdir_p(job_dir) on line 49 creates the literal directory (no shell) and succeeds even when the name contains $()/;, so execution reaches the sh call.<br /> <br /> Affected versions:<br /> - BOSH Director: all versions prior to v282.1.12 (inclusive); fixed in v282.1.12 or later