THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54231 (MEDIUM 5.5) — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont

[NVD] CVE-2026-54231 (MEDIUM 5.5) — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont

lownvdPublished 2026-06-13

CVE-2026-54231 CVSS: 5.5 MEDIUM Published: 2026-06-13T03:16:21.877

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary co

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54231