Junglewise Threat Intelligence

CVE-2026-42168: django-pyas2 OS command injection in Partner model

CVE-2026-42168 · Severity: info · CVSS 7.2 · Published 2026-07-17

Executive brief

django-pyas2 is a server used for secure AS2 file transfers. A security flaw allows an administrative user to execute unauthorized commands on the underlying server by entering malicious text into specific configuration fields. This could lead to a full system takeover, data theft, or disruption of file transfer operations.

Technical details

An OS command injection vulnerability exists in django-pyas2 through version 1.2.3. The 'cmd_receive' and 'cmd_send' fields within the Partner model are passed directly to the 'os.system()' function in 'pyas2/utils.py' without proper sanitization or escaping. An authenticated attacker with administrative privileges can inject arbitrary shell commands into these fields. These commands are subsequently executed by the server whenever an AS2 message is sent or received, leading to remote code execution (RCE) in the context of the application process.

Affected products

  • abhishek-ram django-pyas2 <= 1.2.3

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References