Impact
The issue allows an authenticated user with job run permission to inject metacharacters such as && or | into option values when executing a job targeting a Windows node. The injected text is passed to the underlying Windows command interpreter even though the CLIUtils.quoteWindowsCMDArg function wraps it in single quotes, resulting in arbitrary command execution. This represents a classic OS command injection flaw (CWE-78).
Affected Systems
Installations of Rundeck up to and including version 6.1.x are affected. The vulnerability resides in the CLIUtils component of the Rundeck core that processes job options for Windows nodes.
Risk and Exploitability
The CVSS score of 7.7 indicates a moderate to high potential impact if exploited. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly known exploits yet. Attackers would need authenticated credentials with job run permissions; once privileged, they can execute arbitrary commands with the node executor's user context, potentially compromising the target Windows system.
OpenCVE Enrichment