OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2022-51019 (CVSS 8.7)

NVD · officialPublished Sep 29, 2026Risk 37/100

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.

CVSS
8.7
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source