OVERVIEW CVE-2026-40030 is an OS command injection vulnerability in parseusbs versions before 1.9. The flaw exists in the volume listing functionality where user-supplied input via the -v flag is passed unsanitized directly to an os.popen() shell command with the ls utility. This allows attackers to inject arbitrary shell commands by crafting malicious volume path arguments containing shell metacharacters. SEVERITY The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring user interaction but no special privileges. Exploitation has no complexity barriers and delivers complete compromise of system confidentiality, integrity, and availability. The FAUCET Risk Score of 49.0/100 indicates moderate concern, though EPSS scoring places it below typical vulnerability prevalence thresholds. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and the vulnerability does not appear on the Known Exploited Vulnerabilities catalog. However, the straightforward nature of command injection and the low technical barriers to exploitation present realistic attack risk. Community attention appears limited given the relatively niche nature of the parseusbs utility and the early-stage CVSS assessment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9CPE matchmatch criteria | cpe:2.3:a:khyrenz:parseusbs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.