---
id: CVE-2024-29640
aliases:
  - GHSA-73v2-rxqp-7q4f
  - PYSEC-2026-1114
title: aliyundrive-webdav vulnerable to Command Injection
summary: aliyundrive-webdav vulnerable to Command Injection
severity: high
vendor: aliyundrive-webdav
product: aliyundrive-webdav
ecosystem: rust
affected:
  - aliyundrive-webdav <= 2.3.3
  - aliyundrive-webdav <= 2.3.3
published: '2024-03-29'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-73v2-rxqp-7q4f'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-29640'
  - url: 'https://github.com/lakemoon602/vuln/blob/main/detail.md'
  - url: 'https://github.com/messense/aliyundrive-webdav'
  - url: >-
      https://github.com/messense/aliyundrive-webdav/blob/main/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.lua
  - url: 'http://aliyundrive-webdav.com'
tags:
  - osv
  - rust
epss: 0.01179
epssPercentile: 0.6631
ingestedAt: '2026-07-08T18:25:46.750Z'
---

## Overview

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the `action_query_qrcode` component.

## Affected packages

- `aliyundrive-webdav <= 2.3.3`
- `aliyundrive-webdav <= 2.3.3`

## Remediation

Refer to the advisory for the patched release.
