VDB
Sign up
—

PYSEC-2026-1114

aliyundrive-webdav vulnerable to Command Injection

Details

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aliyundrive-webdav
Introduced in: 0

No fixed version published yet for aliyundrive-webdav (pip). Pin to a known-safe version or switch to an alternative.

References