id: PYSEC-2026-1114 published: "2026-07-07T11:45:37.035521Z" modified: "2026-07-07T17:23:39.046472Z" aliases: - CVE-2024-29640 - GHSA-73v2-rxqp-7q4f summary: aliyundrive-webdav vulnerable to Command Injection details: An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component. affected: - package: name: aliyundrive-webdav ecosystem: PyPI purl: pkg:pypi/aliyundrive-webdav ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 2.3.3 versions: - 0.1.0 - 0.1.1 - 0.1.10 - 0.1.11 - 0.1.12 - 0.1.13 - 0.1.14 - 0.1.15 - 0.1.16 - 0.1.17 - 0.1.18 - 0.1.19 - 0.1.2 - 0.1.20 - 0.1.21 - 0.1.22 - 0.1.23 - 0.1.24 - 0.1.25 - 0.1.26 - 0.1.27 - 0.1.3 - 0.1.4 - 0.1.5 - 0.1.6 - 0.1.7 - 0.1.8 - 0.1.9 - 0.2.0 - 0.2.1 - 0.3.0 - 0.3.1 - 0.3.2 - 0.4.0 - 0.4.1 - 0.4.2 - 0.4.3 - 0.4.4 - 0.4.5 - 0.4.6 - 0.4.7 - 0.4.8 - 0.5.0 - 0.5.1 - 0.5.2 - 0.5.3 - 0.5.4 - 0.5.5 - 1.0.0 - 1.1.0 - 1.1.1 - 1.10.0 - 1.10.1 - 1.10.2 - 1.10.3 - 1.10.4 - 1.10.5 - 1.10.6 - 1.10.7 - 1.11.0 - 1.2.0 - 1.2.1 - 1.2.2 - 1.2.3 - 1.2.4 - 1.2.5 - 1.2.6 - 1.2.7 - 1.3.0 - 1.3.1 - 1.3.2 - 1.3.3 - 1.4.0 - 1.5.0 - 1.5.1 - 1.6.0 - 1.6.1 - 1.6.2 - 1.7.0 - 1.7.1 - 1.7.2 - 1.7.3 - 1.7.4 - 1.8.0 - 1.8.1 - 1.8.2 - 1.8.3 - 1.8.4 - 1.8.5 - 1.8.6 - 1.8.7 - 1.8.8 - 1.8.9 - 1.9.0 - 2.0.0 - 2.0.1 - 2.0.2 - 2.0.3 - 2.0.4 - 2.0.5 - 2.1.0 - 2.2.0 - 2.2.1 - 2.2.2 - 2.3.0 - 2.3.1 - 2.3.2 - 2.3.3 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-29640 - type: WEB url: https://github.com/lakemoon602/vuln/blob/main/detail.md - type: PACKAGE url: https://github.com/messense/aliyundrive-webdav - type: WEB url: https://github.com/messense/aliyundrive-webdav/blob/main/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.lua - type: WEB url: http://aliyundrive-webdav.com - type: PACKAGE url: https://pypi.org/project/aliyundrive-webdav - type: ADVISORY url: https://github.com/advisories/GHSA-73v2-rxqp-7q4f