Impact
The vulnerability resides in the way the scriptPath parameter is incorporated into a /bin/sh -c command without proper neutralization of shell metacharacters. This flaw permits an authenticated user to embed shell command substitution syntax, such as $(...), into a resource filename. When the Alert Script plugin triggers the /test-send endpoint, the injected syntax is interpreted by the shell, allowing the attacker to execute arbitrary commands with the privileges of the DolphinScheduler service process. The result is a full remote code execution that could compromise the underlying host and any dependent services.
Affected Systems
Apache DolphinScheduler versions prior to 3.4.3 are affected. Organizations running these versions should review their deployments and confirm the version in use.
Risk and Exploitability
The flaw is a high-severity command injection (CWE‑78). While the CVSS score is not provided, the fact that it allows execution of arbitrary commands with service-level privileges indicates a severe impact. Exploitation requires a valid authenticated session, which is typical in many operational environments. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, but the nature of the vulnerability warrants prompt remediation to mitigate the immediate risk.
OpenCVE Enrichment