Executive brief
Reminiscence is a self-hosted media archiving tool. A security flaw in its media export system allows an authorized user to take full control of the underlying Windows server. By providing a specially crafted setting for the download manager, an attacker can force the server to execute unauthorized system commands, potentially leading to data theft or complete system compromise.
Technical details
An OS command injection vulnerability exists in kanishka-linux Reminiscence v0.3.0 within the media archiving and export pipeline. The vulnerability is rooted in the 'download_manager' setting, which is stored in 'pages/views.py' and later retrieved in 'pages/dbaccess.py'. On Windows deployments, the application formats this user-controlled string with variables like {iurl} and {output} before passing it to a subprocess call with 'shell=True'. An authenticated attacker can inject shell command separators into the 'download_manager' configuration to achieve arbitrary code execution with the privileges of the server process. This issue specifically affects Windows environments where shell-based subprocess execution is utilized.
Affected products
- kanishka-linux Reminiscence 0.3.0
Timeline
- 2026-06-13: disclosed: Initial disclosure via GitHub Gist
- 2026-06-15: advisory: CVE published to NVD