Posted by Wenjun Ruan on Sep 29 Severity: low Affected versions: - Apache DolphinScheduler before 3.4.3 Description: The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the...
CVE-2026-82804: Apache DolphinScheduler: Command Injection in the Alert Script Plugin
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/998
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.





