Executive brief
Kopia is a backup tool used to secure and manage data across various operating systems. A security flaw in its web-based management interface allows an unauthenticated attacker to execute arbitrary commands on the host system. This could lead to a total system takeover, data theft, or the destruction of backups. The vulnerability is particularly dangerous when the server is configured to run without a password and is accessible over a network.
Technical details
A remote code execution (RCE) vulnerability exists in Kopia's HTTP server due to missing authentication and improper input validation. When started with the '--without-password' flag, the server allows unauthenticated access to the '/api/v1/repo/exists' endpoint. An attacker can submit a crafted JSON request containing an SFTP storage configuration with 'externalSSH: true' and malicious 'sshArguments'. Specifically, by injecting '-oProxyCommand=<cmd>', the attacker leverages OpenSSH's behavior to execute arbitrary shell commands via 'exec.CommandContext'. This occurs because the application splits arguments only on spaces without proper sanitization or shell-style tokenization. The issue is fixed in version 0.23.0, which restricts unauthenticated servers to loopback interfaces by default.
Affected products
- Kopia Kopia <= 0.22.3
Timeline
- 2026-05-05: patched: Initial fix commit and pull request submitted
- 2026-05-12: other: Version 0.23.0 released
- 2026-05-13: advisory: GitHub Security Advisory published
- 2026-07-16: disclosed: CVE published to NVD