Executive brief
Proxmox Mail Gateway's API contains a vulnerability in its package changelog retrieval functionality that allows argument injection attacks. An authenticated attacker can exploit this to inject malicious arguments into system commands, potentially leading to unauthorized command execution or information disclosure. While authentication is required, the vulnerability can be leveraged in CSRF-style attacks against administrative users.
Technical details
The vulnerability exists in pmg-api's package changelog endpoint where user-supplied input is insufficiently sanitized before being passed to underlying apt-get commands. An authenticated attacker can inject shell arguments to alter command behavior. The attack vector requires prior authentication but does not require explicit user interaction beyond normal API access.
Affected products
- Proxmox Mail Gateway pmg-api <UNKNOWN>
Timeline
- 2026-09-21: disclosed