Impact
The vulnerability occurs when Wgcloud 3.6.4 concatenates the content parameter directly into the ProcessBuilder command without sanitization. This allows a remote attacker to inject arbitrary operating‑system commands, resulting in remote code execution and privilege escalation on the host running the service. The flaw represents a classic command injection vulnerability (CWE‑78).
Affected Systems
Affected systems are deployments of Wgcloud 3.6.4. No vendor or product subdivision is specified, but any instance running this exact version is susceptible. The only publicly available reference is a GitHub advisory; there is no announced patch or update within this data set.
Risk and Exploitability
The CVSS score is not provided, nor is an EPSS figure; KEV status is not listed. Despite the lack of quantitative metrics, the ability to freely execute commands over the network without authentication indicates a high risk. The likely attack path involves a remote client sending a crafted content value to an exposed endpoint; no privileged context or additional authentication is implied.
OpenCVE Enrichment