๐Ÿ” CVE Alert

CVE-2026-28673

HIGH 7.2

xiaoheiFS Vulnerable to RCE via Unrestricted Plugin Installation (Manifest Manipulation)

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin system allows admins to upload a ZIP file containing a binary and a `manifest.json`. The server trusts the `binaries` field in the manifest and executes the specified file without any validation of its contents or behavior, leading to Remote Code Execution (RCE). Version 0.4.0 fixes the issue.

CWE CWE-78 CWE-434
Vendor danvei233
Product xiaoheifs
Published Mar 18, 2026
Last Updated Mar 18, 2026
Stay Ahead of the Next One

Get instant alerts for danvei233 xiaoheifs

Be the first to know when new high vulnerabilities affecting danvei233 xiaoheifs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

danvei233 / xiaoheiFS
< 0.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/danvei233/xiaoheiFS/security/advisories/GHSA-4vw4-5wmh-7x4v