CVE-2026-108161
Description
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/fusionpbx/fusionpbx
- https://github.com/fusionpbx/fusionpbx/blob/ac4cd29870e3af67506390800904e262fee7e0ec/app/call_recordings/resources/classes/call_recordings.php#L736-L776
- https://github.com/fusionpbx/fusionpbx/commit/074a69310100f95171c67db62643cc2aac4f4d37
- https://www.vulncheck.com/advisories/fusionpbx-through-5.6.5-os-command-injection-via-caller-id-in-recording-zip-download
CWEs
CWE-78
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.