---
id: CVE-2026-102133
title: >-
  An optional, separately licensed repository-connector feature in Kiteworks
  Core did not neutralize special characters in a user-supplied path before
  passing it to an external command
summary: >-
  An optional, separately licensed repository-connector feature in Kiteworks
  Core did not neutralize special characters in a user-supplied path before
  passing it to an external command. An authenticated system administrator could
  inject ad…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:01.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102133'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-53qp-jmrc-2g5j
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.833Z'
---

## Overview

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
