CVE-2026-67180

Summary

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

Affected Software

VendorProductVersion RangeStatus
GoogleTurbinia0 < 2026-07-10affected
GoogleTurbinia2026-07-10unaffected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References