GHSA-qcjq-7f7v-pvc8HighCVSS 8.8

Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF

Published
January 29, 2024
Last Modified
July 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Fix bypass to the following bugs

  • https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-pxmr-q2x3-9x9m
  • https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-8r25-68wm-jw35

Allowing to inject directly in the app.ini via CRLF to change the value of test_config_cmd and start_cmd resulting in an Authenticated RCE

Impact

Authenticated Remote execution on the host

🎯 Affected products1

  • go/github.com/0xJacky/Nginx-UI:< 1.9.10-0.20240126104956-d70e37c8575e

🔗 References (5)