Description
WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

The vulnerability lies in the project task export endpoint of WookTeam, where a base64‑encoded data parameter is decoded and directly fed into a PHP eval call after wrapping it with string2array. Because eval receives the raw content when the decoded string begins with "array", an attacker can embed arbitrary PHP code to be executed with the web server's privileges. This flaw therefore provides a straightforward pathway to remote code execution on any system running the affected software.

Affected Systems

The flaw affects all deployments of WookTeam version 1.6.6 and earlier. The product name is WookTeam and there are no known vendor identifiers listed. Applications using these versions should verify which version they run and determine whether they are exposed to the vulnerable /api/project/task/export interface.

Risk and Exploitability

No EPSS impact score was published and the vulnerability is not listed in CISA’s KEV catalog, but the nature of the flaw—unchecked eval on user input—represents a high‑severity issue that can be triggered by sending a crafted request to the exposed API. Because the description does not mention authentication or network restrictions, it is reasonable to infer that the API is reachable by attackers who can reach the host, making the likelihood of exploitation high for exposed instances. The absence of a CVSS score means the actual numeric severity is unknown, but the remote code execution potential warrants immediate attention.

Generated by OpenCVE AI on October 5, 2026 at 16:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch or upgrade to a version newer than 1.6.6 that removes the unsafe eval usage.
  • Restrict the /api/project/task/export endpoint to only authenticated and authorized users, or place a firewall rule to block external access if the feature is not required.
  • If an upgrade is not immediately possible, edit the string2array implementation to sanitize or remove the eval call and replace it with a safe parser, ensuring that only trusted arrays are processed.

Generated by OpenCVE AI on October 5, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title WookTeam Remote Code Execution via Base64-Decoded Eval Injection in Task Export API
Weaknesses CWE-94

Mon, 05 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T15:11:57.066Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88393

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T16:17:16.830

Modified: 2026-10-05T16:17:16.830

Link: CVE-2026-88393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T16:30:20Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')