GHSL-2024-098: Authenticated remote code execution in Elektra - CVE-2024-41961
Published Sep 21, 2026
·Updated
Authenticated Elektra users were able to execute arbitrary code and potentially access otherwise unreachable remote systems; attackers could have also triggered code execution by sending crafted links to authenticated users.
Event History
Sep 21, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
Authenticated Elektra users are directly exposed because they could execute arbitrary code. Authenticated users who receive crafted links may also be exposed if an attacker can induce code execution through those links.
2
What does an attacker need to exploit it?
The issue can be exploited by an authenticated Elektra user. Alternatively, an attacker could send a crafted link to an authenticated user to trigger code execution.
3
What is the potential impact beyond the Elektra environment?
Successful exploitation could allow arbitrary code execution and may enable access to remote systems that would otherwise be unreachable.