CVE-2023-37469: Icewhale Casaos

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a patch for the issue.

Affected products

  • Icewhale Casaos: before 0.4.4 (fixed in 0.4.4)

Published 2023-08-24. Last modified 2026-06-17.