Sabyasachirana · Webmap · CVE-2026-90843
**Name of the Vulnerable Software and Affected Versions**
SabyasachiRana WebMap versions prior to 3d52f65803a2716bff14d938352c6fef45b0cfb6
**Description**
An OS command injection flaw exists in the New Nmap Scan Handler component. The issue occurs within the `nmap newscan()` function located in the `functions nmap.py` file. A remote attacker can exploit this by manipulating the `target/params` argument to execute arbitrary operating system commands.
**Recommendations**
Apply patch 3d52f65803a2716bff14d938352c6fef45b0cfb6 to resolve the issue.
As a temporary workaround, restrict access to the `nmap newscan()` function to minimize the risk of exploitation.