SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
{ "binaries": [ { "binary_name": "sabnzbdplus", "binary_version": "0.7.20+dfsg-1" }, { "binary_name": "sabnzbdplus-theme-classic", "binary_version": "0.7.20+dfsg-1" }, { "binary_name": "sabnzbdplus-theme-iphone", "binary_version": "0.7.20+dfsg-1" }, { "binary_name": "sabnzbdplus-theme-mobile", "binary_version": "0.7.20+dfsg-1" }, { "binary_name": "sabnzbdplus-theme-plush", "binary_version": "0.7.20+dfsg-1" }, { "binary_name": "sabnzbdplus-theme-smpl", "binary_version": "0.7.20+dfsg-1" } ] }