漏洞概述 CVE编号: CVE-2026-67180 标题: Google Turbinia 任意命令执行 描述: Google Turbinia 允许通过工作任务执行任意命令。具有提交处理请求或影响证据路径/名称权限的攻击者可以在工作集群上获得代码执行权限。 CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 更新时间: 2026-08-11 发布时间: 2026-08-11 影响范围 CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ("OS Command Injection") CVSS评分: - 版本3.1: 8.4 (HIGH) - 版本4.0: 7.5 (HIGH) 受影响产品: - 供应商: Google - 产品: Turbinia - 版本: 从0到2026-07-10 修复方案 修复时间: 2026-07-10 其他信息 贡献者: George Chen 参考链接: - github.com (issue-tracking) - github.com (patch) - cve.org (vdb-entry) - raw.githubusercontent.com (third-party-advisory) 总结 Google Turbinia 存在任意命令执行漏洞,攻击者可以通过提交处理请求或影响证据路径/名称来获得代码执行权限。该漏洞已被修复,修复时间为2026-07-10。