Executive brief
Nadesiko3 is a Japanese programming language runtime for Windows. A command injection flaw in the compression and decompression features allows remote attackers to execute arbitrary system commands. This could enable attackers to take full control of affected systems, compromise data, or deploy malware.
Technical details
A CWE-78 OS command injection vulnerability exists in Nadesiko3 (PC/Node.js version) affecting compression and decompression operations. The vulnerability stems from insufficient input sanitization when processing compressed files, allowing an attacker to inject shell commands that execute with the privileges of the application. No authentication or special preconditions are required—a remote attacker can trigger the flaw by supplying a malicious compressed file. The vulnerability affects versions 3.3.68 and earlier. Patches are available in version 3.3.69 and later (released December 2022).
Affected products
- Nadesiko Project Nadesiko3 3.3.68 and earlier
Timeline
- 2022-12-05: disclosed
- 2022-12-05: patched: Version 3.3.69 released with patches