HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
HFS2 version 2.4.0 and earlier suffers from a critical template injection vulnerability in its multipart upload handler that enables unauthenticated remote code execution. By embedding malicious template syntax in filenames—specifically using closing template quoting sequences followed by exec macros—attackers can bypass authorization checks in the dispatcher and execute arbitrary commands on the host system. This vulnerability is particularly dangerous because it requires no authentication, has a CVSS score of 10 (critical), and affects all users of vulnerable HFS2 versions. Organizations using HFS2 for file sharing or transfer operations face immediate risk of complete system compromise, data theft, and lateral movement within their networks.
While this CVE currently has no mapped MITRE ATT&CK techniques and shows zero matching Casky skills, Claude AI's extended reasoning capabilities would detect the attack patterns through behavioral analysis of file upload operations. Practitioners using Casky would observe suspicious indicators such as: anomalous filename patterns containing template syntax characters, dispatcher authorization bypass attempts, unexpected process execution following file uploads, and shell command patterns in access logs. By correlating these signals across the 754 mapped security skills, Claude would help practitioners identify the exploitation chain—likely involving T1190 (Exploit Public-Facing Application) and T1059 (Command and Scripting Interpreter)—enabling faster detection and response before attackers achieve persistent code execution on critical systems.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-97359. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation