WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/fangtang7/CVE/blob/main/WookTeam/rce.md |
|
History
Mon, 05 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WookTeam Remote Code Execution via Base64-Decoded Eval Injection in Task Export API | |
| Weaknesses | CWE-94 |
Mon, 05 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-05T15:11:57.066Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88393
No data.
Status : Received
Published: 2026-10-05T16:17:16.830
Modified: 2026-10-05T16:17:16.830
Link: CVE-2026-88393
No data.
OpenCVE Enrichment
Updated: 2026-10-05T16:30:20Z
Weaknesses