CVE-2026-33145: Xrdp Insecure Alternate Shell Default
The `allow_alternate_shell` configuration is initialized to true (1). This insecure default allows clients to supply arbitrary commands which are executed via /bin/sh without sanitization during RDP connection.
Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Cβ
greprules fetch cve-2026-33145-xrdp-insecure-alternate-shell-default --engine opengrepDescription
The `allow_alternate_shell` configuration is initialized to true (1). This insecure default allows clients to supply arbitrary commands which are executed via /bin/sh without sanitization during RDP connection.
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0