CVE-2026-90843 Details
Description
A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.
An OS command injection vulnerability has been identified in SabyasachiRana WebMap versions prior to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. The issue arises in the New Nmap Scan Handler, specifically within the nmap_newscan function of the functions_nmap.py file. The vulnerability can be exploited remotely by manipulating the target/params argument, leading to unauthorized command execution on the operating system.
Users are advised to update to the version that includes the patch 3d52f65803a2716bff14d938352c6fef45b0cfb6 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://calledstriker.gitbook.io/blog/security-research/webmap | [email protected] | ExploitTechnical Description |
| https://github.com/SabyasachiRana/WebMap/ | [email protected] | Broken LinkVendor |
| https://github.com/SabyasachiRana/WebMap/commit/3d52f65803a2716bff14d938352c6fef45b0cfb6 | [email protected] | Source CodeVendor |
| https://raw.githubusercontent.com/CalledSTRIKER/CalledSTRIKER-gitbook/refs/heads/main/security-research/2026-05-30_12-29.png | [email protected] | Exploit |
| https://vuldb.com/cve/CVE-2026-90843 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/925586 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403395 | [email protected] | Permission Required |
| https://vuldb.com/vuln/403395/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SabyasachiRana WebMap | <= 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion