Lsyncd is a file-synchronization daemon that automates bidirectional or unidirectional directory replication across systems, typically deployed in backup and failover architectures where it operates with elevated filesystem and process privileges. The observed vulnerability signal centers on command-injection weaknesses in the tool's command-execution and scripting interface, a characteristic risk for synchronization utilities that invoke external programs to manage file operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lsyncd Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8990HIGH default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. | Dec 5, 2014 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lsyncd Project.
Media articles that mention a CVE ID that affects a product developed by Lsyncd Project — matched by CVE ID, not by vendor name.