Executive brief
UAC is a digital forensics tool used to collect evidence and artifacts from Unix-like systems. A command injection vulnerability in versions prior to 3.3.0 allows attackers to execute arbitrary commands by embedding malicious shell metacharacters into evidence inputs, filenames, or artifact definitions. An attacker could exploit this to gain code execution on a forensic analyst's computer when processing hostile evidence.
Technical details
The vulnerability is a command injection flaw in the _run_command function caused by unsafe use of eval with untrusted runtime placeholders (%user%, %user_home%, and %line%) that are substituted directly into shell commands without proper escaping. An attacker can inject shell metacharacters or command substitutions through crafted usernames, process names, filenames in mounted images, or tampered artifact definitions. When the analyst processes this evidence, the injected commands execute with the privileges of the UAC process. The fix, merged on 2026-03-28, escapes these runtime placeholders before eval to prevent command injection. No patch adoption timeline is available beyond the fix commit date.
Affected products
- tclahr UAC (Unix-like Artifacts Collector) prior to 3.3.0
Timeline
- 2026-08-21: disclosed: CVE-2026-41449 published
- 2026-03-28: patched: Fix merged in commit 2cc367d; escaping of runtime placeholders implemented