Impact
OpenLiteSpeed before 1.9.3 has a flaw in the admin/misc/lsup.sh script that allows an attacker controlling the web process running as the nobody user to substitute an update package in the /usr/local/lsws/autoupdate/ directory. The script then extracts and executes the install.sh component as root, giving the attacker full system privileges without authentication. This vulnerability exposes the server to complete control over the operating system and any services running on it.
Affected Systems
The affected product is OpenLiteSpeed from LiteSpeed Technologies, in all releases prior to version 1.9.3. The vulnerability is present whenever the auto‑update directory is writable by the nobody user and the unverified install.sh script is executed as root during a normal update cycle.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity, and the EPSS score is not available, suggesting no recent exploitation data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker who can run code as the nobody web process can replace the update package, which then runs with root permissions during the next update. Because the flaw requires local access to the web server, it is contingent on successful compromise of the web-facing component, but once achieved it provides full administrator privileges.
OpenCVE Enrichment