Skip to content

Remote Command Execution in Knowage Community Edition (<= 8.1.37) #952

@Amlreux

Description

@Amlreux

Hello Knowage Team,

I would like to report a security vulnerability I discovered in Knowage Community Edition (<= 8.1.37).
The issue could potentially lead to Remote Command Execution (RCE) under certain conditions.

For responsible disclosure reasons, I will not share the technical details or PoC here publicly.
Could you please provide a proper security contact (email address or private channel) so that I can send you the full report?

Summary

  • Product: Knowage Community Edition
  • Version: <= 8.1.37
  • Vulnerability type: Command Injection → possible Arbitrary Command Execution
  • Impact: Remote attacker may execute arbitrary system commands

I am following responsible disclosure practices and would like to coordinate with the Knowage team before publishing any technical details.

Thank you

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions