Junglewise Threat Intelligence

CVE-2025-30007: HestiaCP OS command injection in DNS record management

CVE-2025-30007 · Severity: high · CVSS 8.8 · Published 2026-07-10

Technologies: HestiaCP. Vendors: HestiaCP.

Executive brief

HestiaCP is an open-source control panel used to manage web servers and hosting environments. A security flaw allows a user with low-level access to take complete control of the server by injecting malicious code into DNS record settings. This could lead to a total system takeover, data theft, or service disruption, as the attacker gains the highest level of administrative (root) privileges.

Technical details

An authenticated OS command injection vulnerability exists in HestiaCP versions prior to 1.9.5. The flaw stems from insufficient input validation in the 'is_dns_record_format_valid()' function combined with unsafe eval-based parsing within 'update_domain_zone()'. By injecting a single-quote character into specific DNS record types, an attacker can prematurely close a variable assignment string to execute arbitrary shell commands. This allows a low-privilege authenticated user to achieve full root code execution on the underlying host. The issue is addressed in version 1.9.5 by hardening DNS record validation.

Affected products

  • HestiaCP HestiaCP < 1.9.5

Timeline

  • 2025-12-23: other: Initial pull request for hardening DNS validation submitted
  • 2026-01-04: patched: Fix merged into main branch
  • 2026-05-28: advisory: Release 1.9.5 published
  • 2026-07-10: disclosed: CVE-2025-30007 published

References

Related threats