PT-2024-28745 · Rejetto · Rejetto Hfs

·

CVE-2024-39943

·

Published

2024-07-04

·

Updated

2026-08-21

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rejetto HFS (aka HTTP File Server) 3 versions prior to 0.52.10
Description Remote authenticated users with upload permissions can execute operating system commands on Linux, UNIX, and macOS. This issue occurs because the software uses a shell to execute the df command via the execSync function instead of spawnSync within the Node.js child process module.
Recommendations Update rejetto HFS (aka HTTP File Server) 3 to version 0.52.10 or later.

Exploit

Fix

OS Command Injection

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12629
CVE-2024-39943
GHSA-5F4X-HWV2-W9W2

Affected Products

Rejetto Hfs