Linagora Twake Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Linagora Twake version 2023.Q1.1223. This issue arises from improper neutralization of special elements used in operating system commands, allowing attackers to inject and execute arbitrary commands. Such exploitation could potentially lead to a complete compromise of the system.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where Twake is running, which could lead to a full system compromise.

Added: Mar 9, 2026, 6:18 PM
Updated: Mar 9, 2026, 6:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
10.0
exploitability
7.4
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.