Executive brief
Synology DiskStation Manager (DSM) is the operating system for Synology NAS devices used by businesses and individuals to store and share data. A CRLF injection vulnerability in the Sharing API allows an authenticated attacker to inject malicious content into sharing URLs, enabling them to write limited files if a victim clicks a malicious sharing link. This could be exploited to modify shared files or redirect users to phishing sites.
Technical details
CVE-2026-13666 is a CRLF injection vulnerability (CWE-93) in the Sharing API component of Synology DSM. The vulnerability stems from improper neutralization of CRLF (carriage return/line feed) sequences in user-supplied input. An authenticated attacker can craft a malicious sharing URL containing CRLF sequences that, when clicked by a victim, allow the attacker to write limited files to the system. The attack requires user interaction (a victim must click the sharing URL) and authentication credentials. Patches are available for affected versions: upgrade to DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Fixed in DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075 or later