Executive brief
FreePBX is an open-source graphical user interface that manages Asterisk, a popular voice-over-IP (VoIP) and telephony server. A security flaw in its API module allows an authorized user to execute malicious commands on the server. This could lead to a complete takeover of the phone system, allowing attackers to intercept calls, access sensitive data, or disrupt communications.
Technical details
A command injection vulnerability exists in the FreePBX 'api' module within the initiateGqlAPIProcess() function. The root cause is the direct passing of GraphQL mutation input fields to the PHP shell_exec() function without proper sanitization or escaping. An authenticated attacker with a valid bearer token can exploit this by sending a GraphQL 'moduleOperations' mutation containing backtick-wrapped shell commands in the 'module' field. Successful exploitation allows for arbitrary command execution on the underlying host with the privileges of the web server user. A patch has been identified in commit 5f194e3.
Affected products
- FreePBX api module 17.0.8 and prior
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory
- 2026-04-21: patched: Patch commit 5f194e3 released
References
- https://github.com/FreePBX/api/blob/5f194e39a47e5481e8947f9694304d32724175f6/Api.class.php
- https://github.com/FreePBX/api/blob/5f194e39a47e5481e8947f9694304d32724175f6/ApiGqlHelper.class.php
- https://github.com/FreePBX/api/commit/5f194e39a47e5481e8947f9694304d32724175f6
- https://www.vulncheck.com/advisories/freepbx-api-module-command-injection-via-graphql