stamparm Maltrail Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability allowing unauthenticated remote code execution exists in stamparm Maltrail versions through 0.54. The issue arises from improper handling of user input in the username parameter of POST requests to the /login endpoint. This vulnerability allows attackers to inject arbitrary operating system commands, which are executed with the same privileges as the Maltrail process.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where Maltrail is running.

Reproduction

To reproduce this vulnerability, send a POST request to the /login endpoint with a payload that includes injected commands in the username parameter. The injected commands will be executed on the server.

Remediation

Users can update to Maltrail version 0.55 or later, where this vulnerability has been fixed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
0.2
threat
7.7
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.