In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qbittorrent | Aug 22, 2024 | Jul 17, 2019 |
| Debian | — | Upgrade qbittorrent | Apr 6, 2020 | Jul 17, 2019 |
| Suse | — | Upgrade qbittorrentUpgrade qbittorrent-nox | Aug 27, 2019 | Jul 17, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub