FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCISA ADP Vulnrichment affects Soliton Systems K.K./FileZen (generic), Soliton Systems K.K./FileZen (generic). Severity is high. This vulnerability is known to be exploited in the wild. FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Soliton Systems K.K./FileZengeneric | V5.0.0 to V5.0.10 | Not reported |
| Soliton Systems K.K./FileZen |
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCISA ADP Vulnrichment affects Soliton Systems K.K./FileZen (generic), Soliton Systems K.K./FileZen (generic). Severity is high. This vulnerability is known to be exploited in the wild. FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Soliton Systems K.K./FileZengeneric | V5.0.0 to V5.0.10 | Not reported |
| Soliton Systems K.K./FileZen |
| V4.2.1 to V4.2.8 |
| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| V4.2.1 to V4.2.8 |
| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard