#1145563 sabnzbdplus: remote code execution, path traversal vulnerabilities

Package:
src:sabnzbdplus
Source:
src:sabnzbdplus
Submitter:
Jeroen Ploemen
Date:
2026-08-25 16:23:03 UTC
Severity:
normal
Tags:
#1145563#5
Date:
2026-08-25 15:54:43 UTC
From:
To:
Hi,

two separate vulnerabilities were discovered in sabnzbdplus that
involve remote code execution and a directory traversal. No CVEs have
been issued yet.

* remote code execution vulnerability: in version 5.1.1 and earlier,
  an attacker who can reach the web interface could bypass
  authentication on privileged configuration endpoints and, from
  there, execute arbitrary commands on the system running SABnzbd.
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-rgqj-28c2-gxwp

* path traversal vulnerability: in version 5.1.1 and earlier, a
  maliciously crafted PAR2 or SFV file inside a download could make
  SABnzbd write files outside the job’s own folder during
  post-processing, which could be escalated to execute arbitrary
  commands on the system running SABnzbd.
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r


Both issues are fixed in upstream release 5.1.2, the relevant commits
are the following:

For the remote code execution:
https://github.com/sabnzbd/sabnzbd/commit/a0e24089338e4a9b214a439e6dba2ee489195847
https://github.com/sabnzbd/sabnzbd/commit/6525703a94cfdb6c8add5c6f91bc073a7e928ed5

For the path traversal:
https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0
https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8


I'll upload the new upstream release to unstable today, and intend to
prepare patches for older Debian releases as soon as possible.

#1145563#10
Date:
2026-08-25 16:20:58 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
sabnzbdplus, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145563@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeroen Ploemen <jcfp@debian.org> (supplier of updated sabnzbdplus package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 25 Aug 2026 16:07:23 +0000
Source: sabnzbdplus
Built-For-Profiles: noudeb
Architecture: source
Version: 5.1.2+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Jeroen Ploemen <jcfp@debian.org>
Changed-By: Jeroen Ploemen <jcfp@debian.org>
Closes: 1145563
Changes:
 sabnzbdplus (5.1.2+dfsg-1) unstable; urgency=medium
 .
   * New upstream release:
     + fixes two vulnerabilities. (Closes: #1145563)
   * Patches: refresh 02, 08, and 10.
Checksums-Sha1:
 fc88d545e713e629d85323df27751f135cddbf00 2310 sabnzbdplus_5.1.2+dfsg-1.dsc
 5c4058d2422dd89b985b08e03e0caf41531dcc8e 5911595 sabnzbdplus_5.1.2+dfsg.orig.tar.gz
 4cf7c90257c547c13b68b3e06fafbf4671a722d3 30284 sabnzbdplus_5.1.2+dfsg-1.debian.tar.xz
 13a7d5748afabe60d2fac488041cf97db296c8c1 8222 sabnzbdplus_5.1.2+dfsg-1_source.buildinfo
Checksums-Sha256:
 e80175b5e76ff65077e4710fb0c281f7121625bc5fc6b655108471d3b33532a5 2310 sabnzbdplus_5.1.2+dfsg-1.dsc
 44f4f377d7d4fa8e6b288238699ac30fc323d974821e4ff6ad82187283e2a5cf 5911595 sabnzbdplus_5.1.2+dfsg.orig.tar.gz
 003bde665c0ea2a02e5772b0d594c8b5d1f654426a64488fa0ae2a164f24a03e 30284 sabnzbdplus_5.1.2+dfsg-1.debian.tar.xz
 2cb3a812841499cb977a61d3143690c98791bc117372f9f32b29fd0ad2516c5d 8222 sabnzbdplus_5.1.2+dfsg-1_source.buildinfo
Files:
 324edeac1bb0bb2e94df1656a2630ca3 2310 contrib/net - sabnzbdplus_5.1.2+dfsg-1.dsc
 dbb625a122ce15aad8b645602d970669 5911595 contrib/net - sabnzbdplus_5.1.2+dfsg.orig.tar.gz
 1ed7a37c19d59d2355460a8f5e614698 30284 contrib/net - sabnzbdplus_5.1.2+dfsg-1.debian.tar.xz
 d5179d41138d49064778e7975cbcef7c 8222 contrib/net - sabnzbdplus_5.1.2+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEd8lhnEnWos3N8v+qQoMEoXSNzHoFAmqNvdMACgkQQoMEoXSN
zHqvXhAAlTlfB8VBKqZC+24d7I+UaIfCdj8rP1V+InqvY00m9rke80R1duSc04kA
5x5jjJKEbsVDYY+wR/M7tckxNpNYntt9rJ40LcWr9YhVfeTNViESjCFJ0B5eTxHL
W7K+QQ8MjrBwBlfEQGHAiIV6vgRvhDhSvvqNJ5MsmtRBx+cX4m+yTXUMmveUXgca
1RUwybqbfq/Kl3oXtQok5CuXcqycjcUOjXBwGKurVGet3FRw0q8cBnzm8/KKoIbz
eqLqAamco18LZJ7cDppTq00S9G2It6MXRVR8UB1l8aEWHqCDf+0V4fnTPeiB5SMi
2kbqOTcv/0g8hP+0Tw2BGylm6baJvGjQZgqYbPsLDXMR6m6W+dh7Qi0pU2oY26I7
g+Q/x9m5Zfdw0TpWa2TY42QHWoJgd90CIrnFN18kiOTHt3xY5ZJbjhMIK1qoYY6j
wfHW1SFrpcENCP2GFrh4pStw2O6EdOADlahM4e5ixfN9+iqyZi6MnmmLLDcIo7ZB
8ZFJzAW1PxYFatZ0ht36HBXaFYIf2dVPZeZa8pVDeW+zuwj9QcSQw8/e3cmNDI/x
Ju5Kf+xKBFQ3+GlEVR3Jy4St+dU87VpYQS3bY4RmOe2EPc/oHJh0idsXIMwCoGbc
DDZ+twXOjr9c0UXidr+z72v9igepJKHVHipp4tlEKTk1nVNrqhQ=
=uDiz
-----END PGP SIGNATURE-----