
Praetorian's Khael Kugler found and disclosed a critical vulnerability in AperiSolve, the popular steganography analysis tool used widely in CTFs and the security community. 🚨 CVE-2026-34977 – CVSS 9.3 Unauthenticated RCE via command injection in the JPSeek analyzer functionality. When uploading JPEGs, a password gets interpolated directly into a bash command without sanitization — giving immediate access to the host or container. 🔧 Version 3.2.1 patched. Advisory ➡ https://buff.ly/sbumVHn CVE ➡ https://buff.ly/P0ZPpvc #CVE #OffensiveSecurity
Post summary
Praetorian disclosed a high‑severity CVE-2026-34977 RCE flaw in AperiSolve, detailing its mechanics, CVSS score, and that version 3.2.1 includes a patch.


