Junglewise Threat Intelligence

CVE-2025-14601: vsDesk OS command injection in Task Scheduler

CVE-2025-14601 · Severity: info · CVSS 8.6 · Published 2026-08-20

Technologies: vsDesk. Vendors: vsDesk.

Executive brief

vsDesk is a web server application used to manage tasks and server operations. An authenticated administrator could inject arbitrary operating system commands through insufficient input filtering, potentially leading to full server compromise, data exposure, or service disruption.

Technical details

The vulnerability is an OS command injection flaw in the vsDesk Task Scheduler component caused by insufficient input filtering. It requires network access and valid administrative credentials to exploit. An authenticated attacker with administrative privileges can execute arbitrary shell commands on the underlying operating system, potentially achieving complete server compromise. The vulnerability affects vsDesk versions prior to 14.0101; patches are available from the vendor at https://vsdesk.ru/.

Affected products

  • vsDesk vsDesk before 14.0101

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Version 14.0101 and later include patch

References

Related threats