Icecoder Vulnerabilities: Path Traversal and OS Command Injection Discovered

Icecoder Vulnerabilities: Path Traversal and OS Command Injection Discovered

First seen 10 Sep 2026, 16:01 UTC www.vulncheck.com 39.8

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in Icecoder versions through 8.1. The first, a path traversal vulnerability (CWE-22), allows unauthorized file access due to ineffective file check confinement. The second, an OS command injection vulnerability (CWE-78), arises from improper handling of special elements in the lib properties PHP file. Both vulnerabilities could potentially lead to significant security breaches, affecting users of Icecoder. No specific CVEs were mentioned in the articles, and there is no indication of active exploitation at this time. Security professionals are advised to monitor the situation closely and apply any forthcoming patches. The vulnerabilities were disclosed on September 10, 2026.

Key Points: • Two critical vulnerabilities found in Icecoder versions through 8.1. • Path traversal (CWE-22) and OS command injection (CWE-78) vulnerabilities identified. • No active exploitation confirmed, but vigilance is advised.

Ask AI about this cluster

Timeline

2026-09-10
Vulnerabilities disclosed
Icecoder vulnerabilities related to path traversal and OS command injection were publicly disclosed.
Vulncheck
2026-09-10
Security advisory issued
Security professionals are urged to monitor the vulnerabilities and prepare for potential patches.
Vulncheck