{"id":"CVE-2024-29640","aliases":["PYSEC-2026-1114"],"url":"https://o3.security/vulnerability/CVE-2024-29640","summary":"aliyundrive-webdav vulnerable to Command Injection","details":"An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component.","published":"2024-03-29T18:30:42Z","modified":"2026-07-07T17:56:45.506618367Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"aliyundrive-webdav","fixedVersion":null},{"ecosystem":"PyPI","name":"aliyundrive-webdav","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29640"},{"type":"WEB","url":"https://github.com/lakemoon602/vuln/blob/main/detail.md"},{"type":"PACKAGE","url":"https://github.com/messense/aliyundrive-webdav"},{"type":"WEB","url":"https://github.com/messense/aliyundrive-webdav/blob/main/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.lua"},{"type":"WEB","url":"http://aliyundrive-webdav.com"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:45.506618367Z"}}