Impact
The vulnerability is an arbitrary file write mistake caused by the repository‑connector feature of Kiteworks Core. It allows an authenticated system administrator to supply a file path that is not sanitized before being given to a shell command. The flaw can be exploited to write any content to files owned by the connector’s service account, opening the door for execution of arbitrary code in that account’s context. The weakness is a classic command injection situation described by CWE‑77.
Affected Systems
Kiteworks Core contains the vulnerable connector. No specific version list is supplied, so any deployment that has the repository‑connector enabled and applies a license that activates the feature is at risk. The vulnerability exists in the component that handles user‑supplied paths for external commands.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity. There is no EPSS data available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be an authenticated system administrator and must have network egress from the appliance to a system under the attacker’s control to receive the injected file. The attack vector is inferred: an attacker must already have administrative access and an outbound channel to a controlled host to supply the payload path. If these conditions are met, code execution runs as the connector service account, granting powerful system capabilities.
OpenCVE Enrichment