parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsanitized into an os.popen() shell command, allowing arbitrary command execution via crafted .lnk filenames containing shell metacharacters. An attacker can craft a .lnk filename with embedded shell metacharacters that execute arbitrary commands on the forensic examiner's machine during USB artifact parsing.
History

Thu, 09 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Khyrenz
Khyrenz parseusbs
Vendors & Products Khyrenz
Khyrenz parseusbs

Wed, 08 Apr 2026 21:45:00 +0000

Type Values Removed Values Added
Description parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsanitized into an os.popen() shell command, allowing arbitrary command execution via crafted .lnk filenames containing shell metacharacters. An attacker can craft a .lnk filename with embedded shell metacharacters that execute arbitrary commands on the forensic examiner's machine during USB artifact parsing.
Title parseusbs < 1.9 Command Injection via Crafted LNK Filename
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-04-08T21:35:24.801Z

Updated: 2026-04-09T14:48:31.844Z

Reserved: 2026-04-08T13:36:49.290Z

Link: CVE-2026-40029

cve-icon Vulnrichment

Updated: 2026-04-09T14:48:28.046Z

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:23.303

Modified: 2026-04-08T22:16:23.303

Link: CVE-2026-40029

cve-icon Redhat

No data.