quoteOrEscapeShellPath of the file backend/sftp/sftp.go of the component sftp. Such manipulation leads to os command injection.This vulnerability is listed as CVE-2026-71312. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
SOCIAL SHARE CARD GENERATOR