CVE-2026-44666
HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its strip list. User input then reaches shell_exec(), where the shell interprets these characters and commands within filenames execute. This vulnerability is fixed in 3.3.8.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/zelon88/HRConvert2/releases/tag/v3.3.8, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44666.json, https://github.com/zelon88/HRConvert2/security/advisories/GHSA-f74g-4wj8-j35h, https://nvd.nist.gov/vuln/detail/CVE-2026-44666