In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.1.7-1", "binary_name": "qbittorrent" }, { "binary_version": "4.1.7-1", "binary_name": "qbittorrent-dbg" }, { "binary_version": "4.1.7-1", "binary_name": "qbittorrent-nox" } ] }