CVE-2026-40029 is an OS command injection vulnerability in parseUSBs versions before 1.9, where unsanitized .lnk file paths are passed directly into shell commands via os.popen(), enabling arbitrary command execution. An attacker can craft malicious .lnk filenames containing shell metacharacters that execute arbitrary commands when a forensic examiner processes USB artifacts using the affected tool. The vulnerability has a CVSS score of 7.8 (HIGH) with a local attack vector requiring user interaction but no special privileges. The impact is severe, allowing an attacker to achieve high-level compromise of confidentiality, integrity, and availability on the examiner's machine during routine forensic analysis activities. There is currently no evidence of active exploitation, with an EPSS score of 0.00028 indicating minimal real-world exploit activity. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and shows low community attention, though organizations using parseUSBs for digital forensics should still prioritize updating to version 1.9 or later to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9CPE matchmatch criteria | cpe:2.3:a:khyrenz:parseusbs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.