CVE-2026-53975: OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UIPASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenChamberto a version that resolves this vulnerability.Fixed in 1.11.7 - Configuration
Configure UI_PASSWORD so the authentication middleware is not a no-op; do not use the default Docker deployment behavior where UI_PASSWORD is not set and /api/fs/exec becomes unauthenticated.
OpenChamber UI_PASSWORD = configured - Configuration
Ensure /api/fs/exec requires authentication/authorization and is not accessible to unauthenticated users; this prevents the unauthenticated RCE via crafted POST requests to /api/fs/exec.
OpenChamber /api/fs/exec endpoint authorization = required