THREAT OPS › Threat News › [GHSA] GHSA-rh9c-rqvg-f7pr (medium) — linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
[GHSA] GHSA-rh9c-rqvg-f7pr (medium) — linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
GHSA-rh9c-rqvg-f7pr Severity: medium CVE: CVE-2026-73974
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
## Summary Every Linuxfabrik check plugin that supports the shared `--test` argument (routed through `lib.lftest.test()`) will, when `--test` is supplied, treat the first CSV element as a filesystem path and read its ful
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-73974cve
- CVE-2026-52817cve
Original source: https://github.com/advisories/GHSA-rh9c-rqvg-f7pr