Impact
The vulnerability occurs when Wgcloud 3.6.4 concatenates the content parameter directly into the ProcessBuilder command without sanitization. This allows a remote attacker to inject arbitrary operating system commands, resulting in remote code execution and privilege escalation on the host running the service. The flaw represents a classic command injection vulnerability (CWE-77).
Affected Systems
Affected systems are deployments of Wgcloud 3.6.4. No vendor or product subdivision is specified, but any instance running this exact version is susceptible. The only publicly available reference is a GitHub advisory; there is no announced patch or update within this data set.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate risk. The EPSS score is less than 1%, suggesting a very low but non‑zero likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. The flaw allows a remote unauthenticated attacker to inject arbitrary operating‑system commands via the content parameter, leading to remote code execution and privilege escalation on the host running Wgcloud. The attack requires only the ability to send a crafted request to the exposed endpoint; no privileged context or prior authentication is needed.
OpenCVE Enrichment