Junglewise Threat Intelligence

CVE-2026-50874: kanishka-linux Reminiscence OS command injection in media component

CVE-2026-50874 · Severity: info · CVSS 7.2 · Published 2026-06-15

Executive brief

A security vulnerability exists in the Reminiscence and Shaark self-hosted bookmarking platforms. An administrative user can manipulate system settings to run unauthorized commands on the underlying server. This could allow an attacker with administrative access to take full control of the server, access sensitive files, or disrupt services.

Technical details

An OS command injection vulnerability exists in the /manage/features/media and /manage/features/pdf components of Shaark (v1.2.44) and Reminiscence (v0.3.0). The application stores administrator-controlled binary paths, such as 'node_bin' and 'youtube_dl_bin', without proper validation. When a user accesses the feature-check endpoints, the FeaturesController concatenates these paths into a shell command string and executes them via the PHP exec() function. An attacker with administrative privileges can inject shell metacharacters into these configuration values to achieve arbitrary code execution with the privileges of the web server process.

Affected products

  • kanishka-linux Reminiscence 0.3.0
  • Shaark Shaark 1.2.44

Timeline

  • 2026-06-13: disclosed: Initial discovery and Gist publication
  • 2026-06-15: advisory: CVE-2026-50874 published

References

Related threats