Cloud Foundry disclosed CVE-2026-41010, a high-severity OS command injection vulnerability in BOSH Director that can lead to code execution during release extraction. The flaw resides in ReleaseJob#unpack, where an attacker-controlled job name from release.MF inside an uploaded tarball is used to construct file paths and is then interpolated into a shell command executed through Bosh::Common::Exec.sh, which invokes /bin/sh -c.
Because shell metacharacters in the job name are interpreted by the shell, a crafted release can trigger arbitrary command execution even though FileUtils.mkdir_p creates the directory literally and does not block malicious characters before the shell call. Cloud Foundry said versions of BOSH Director prior to v282.1.12 are affected and that the issue is fixed in v282.1.12 and later, making prompt upgrades critical for environments that upload or process untrusted BOSH releases.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A command injection vulnerability in BOSH Director's ReleaseJob#unpack logic was fixed in version 282.1.12. The flaw stemmed from unsafe handling of an attacker-controlled job name from release.MF that could be interpolated into a shell command during tar extraction.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.