---
id: CVE-2026-63725
title: >-
  sysPass's FileBackupService::doBackupFiles() in
  lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar
  shell command by string-concatenating the backup directory path $this->path
  directly into the command line ('tar cz…
summary: >-
  sysPass's FileBackupService::doBackupFiles() in
  lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar
  shell command by string-concatenating the backup directory path $this->path
  directly into the command line ('tar cz…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-08-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:43:32.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63725'
references:
  - url: 'https://gist.github.com/W40X/6747ba1b7da7bb69b0c0e162628df279'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/nuxsmin/sysPass'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00444
epssPercentile: 0.35994
ingestedAt: '2026-09-24T20:51:40.185Z'
---

## Overview

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory path $this->path directly into the command line ('tar czf ' . $backupFileApp . ' ' . BASE_PATH . ' --exclude \"' . $this->path . '\" 2>&1') and passes the result to PHP's exec() with no application of escapeshellarg() and no validation of the path against a safe character set. The $this->path value is read from the sysPass configuration, which is persisted in the database and writable through the admin settings API and the admin UI. An administrator (or an attacker who has obtained an admin API token or admin session) can therefore store a backup path containing shell metacharacters and trigger a backup operation to execute arbitrary OS commands as the web server process user (typically www-data or apache). Because sysPass is a password manager whose sole purpose is to hold credentials for other systems, code execution as the web-server user permits reading sysPass's master password and encryption key from memory or configuration files, decrypting every stored credential in the database, exporting the entire password vault, pivoting to internal systems using the disclosed credentials, and installing persistent backdoors on the password-manager host.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
