CVE-2026-28674 PUBLISHED

xiaoheiFS Vulnerable to RCE via Arbitrary Payment Plugin Upload (Automatic Execution)

Assigner: GitHub_M
Reserved: 02.03.2026 Published: 18.03.2026 Updated: 18.03.2026

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the AdminPaymentPluginUpload endpoint lets admins upload any file to plugins/payment/. It only checks a hardcoded password (qweasd123456) and ignores file content. A background watcher (StartWatcher) then scans this folder every 5 seconds. If it finds a new executable, it runs it immediately, resulting in RCE. Version 4.0.0 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor danvei233
Product xiaoheiFS
Versions
  • Version < 0.4.0 is affected

References

Problem Types

  • CWE-434: Unrestricted Upload of File with Dangerous Type CWE
  • CWE-798: Use of Hard-coded Credentials CWE