CVE-2026-90843: SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection
A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmapnewscan of the file functionsnmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SabyasachiRana WebMap (New Nmap Scan Handler)to a version that resolves this vulnerability.Patch 3d52f65803a2716bff14d938352c6fef45b0cfb6 - Compensating control
Because the nmap_newscan function in functions_nmap.py (New Nmap Scan Handler) is vulnerable to remote os command injection via manipulation of the target/params argument, restrict network/firewall access to the WebMap component and its Nmap scan functionality to trusted sources only until the silent patch is applied.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker can launch the attack remotely and does not need privileges or user interaction, according to the supplied severity vector. Exploitation targets the New Nmap Scan Handler's target or params arguments.
Are publicly available exploits a concern?
Yes. The exploit has been publicly disclosed and may be used, so exposed instances should be treated as at increased risk.
What remediation is identified?
Apply patch 3d52f65803a2716bff14d938352c6fef45b0cfb6. The issue was fixed through a silent patch.