THREATOPS
THREAT OPSThreat News › Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path

Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path

lowfulldisclosurePublished 2026-08-26

<p>Posted by Ron E on Aug 26</p>An OS command injection vulnerability exists in the Escargot<br /> v4.3.0-214-gfaee4437 crash handler due to an executable/module path being<br /> incorporated into an addr2line shell command without quoting or escaping.<br /> The resulting command is executed using system(), causing shell<br /> metacharacters contained within the path to be interpreted as command<b

Original source: https://seclists.org/fulldisclosure/2026/Aug/108