Junglewise Threat Intelligence

CVE-2026-25855: OpenBullet2 remote code execution in FileProxySource

CVE-2026-25855 · Severity: high · CVSS 8.8 · Published 2026-06-08

Technologies: OpenBullet2. Vendors: OpenBullet2.

Executive brief

OpenBullet2, a popular automation suite for web testing, contains a security flaw that allows users with login access to take full control of the server. By uploading malicious script files through the proxy management feature, an attacker can execute commands directly on the underlying operating system. This could lead to the theft of sensitive data, complete service disruption, or the server being used as a staging ground for further attacks.

Technical details

An OS command injection vulnerability (CWE-78) exists in OpenBullet2 versions 0.2.5 through 0.3.2. The flaw is located in the FileProxySource proxy loading feature, which fails to properly neutralize script files (such as .bat, .ps1, or .sh) uploaded as proxy sources. An authenticated attacker can upload a malicious script, which the server then executes to retrieve proxy lines. This results in arbitrary command execution on the host system with the privileges of the process user. The attack is reachable over the network and requires low-level authentication.

Affected products

  • OpenBullet2 OpenBullet2 0.2.5 through 0.3.2

Timeline

  • 2026-06-08: disclosed
  • 2026-06-08: advisory

References

Related threats