---
id: CVE-2022-51019
title: >-
  Akaunting before 2.1.31 contains an OS command injection vulnerability in the
  module installation and update flow where the alias parameter is passed
  unvalidated to shell command execution
summary: >-
  Akaunting before 2.1.31 contains an OS command injection vulnerability in the
  module installation and update flow where the alias parameter is passed
  unvalidated to shell command execution. Authenticated users with admin panel
  access can…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: akaunting
product: akaunting
affected:
  - akaunting < 2.1.31
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T17:17:00.653'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-51019'
references:
  - url: 'https://github.com/akaunting/akaunting'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/akaunting/akaunting/blob/2.1.30/app/Jobs/Install/FinishUpdate.php#L45-L47
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/akaunting/akaunting/blob/2.1.30/app/Jobs/Install/InstallModule.php#L37-L39
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/akaunting/akaunting/commit/a1792327347a56ea575240b58673b2ece44230da
    label: disclosure@vulncheck.com
  - url: 'https://github.com/akaunting/akaunting/releases/tag/2.1.31'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/akaunting-before-2.1.31-os-command-injection-via-app-alias
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T17:28:50.554827Z'
ingestedAt: '2026-09-29T16:39:33.279Z'
---

## Overview

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
