OS command injection in GUI backup options

Summary

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiSandbox 5.0 5.0.0 through 5.0.2 Upgrade to 5.0.3 or above
FortiSandbox 4.4 4.4.0 through 4.4.7 Upgrade to 4.4.8 or above
FortiSandbox 4.2 4.2 all versions Migrate to a fixed release
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release
FortiSandbox Cloud 24 24.1 Fortinet remediated this issue in 24.2 (not released) and hence customers do not need to perform any action.
FortiSandbox Cloud 23 23 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2025-12-09: Initial publication