Junglewise Threat Intelligence

CVE-2026-42881: squinky86 STIGQter local code execution via Export HTML

CVE-2026-42881 · Severity: info · CVSS 8.4 · Published 2026-05-14

Executive brief

STIGQter is an open-source tool used by security auditors to manage DISA STIG compliance checklists. A vulnerability in how the application handles project files allows an attacker to execute malicious code on a user's computer. To be successful, an attacker must trick a user into opening a specially crafted project file and then clicking the "Export HTML" button, which could lead to a full system compromise or unauthorized data access.

Technical details

A path traversal and arbitrary file write vulnerability exists in STIGQter's 'Export HTML' functionality. The application fails to sanitize the 'STIG.fileName' and 'variables.HTMLHeader' values retrieved from a loaded .stigqter project file (which is a compressed SQLite database). Because QDir::filePath() returns absolute paths unchanged, an attacker can specify absolute paths in the database to write files outside the intended export directory. By crafting a 'polyglot' file that serves as both valid HTML and a valid systemd unit file, an attacker can drop malicious units into the user's systemd configuration directory. Code execution is achieved when the system next reloads user units (e.g., at login). This requires the victim to manually open a malicious project file and initiate an HTML export. The issue is fixed in version 1.2.7 by restricting file paths to the export directory and sanitizing inputs.

Affected products

  • squinky86 STIGQter 0.1.2 to 1.2.6

Timeline

  • 2026-04-23: disclosed: Reported to vendor by Bitwize
  • 2026-04-24: patched: Fixed in upstream master commit d6eb5cb
  • 2026-04-30: advisory: Public disclosure of GHSA-mcv5-5j7p-vqh7
  • 2026-05-14: advisory: CVE-2026-42881 published to NVD

References