{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-20T05:38:53.383","vulnerabilities":[{"cve":{"id":"CVE-2024-49400","sourceIdentifier":"cve-assign@fb.com","published":"2024-10-17T18:15:15.547","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed."},{"lang":"es","value":"Antes de el commit 07b49d1358e6ec0b5aa482fcd284f509191119e2, Tacquito no realizaba correctamente las coincidencias de expresiones regulares en los comandos y argumentos autorizados. Los comandos y argumentos permitidos configurados tenían como objetivo exigir una coincidencia en toda la cadena, pero en su lugar solo aplicaban una coincidencia en una subcadena. Eso podría haber permitido la ejecución de comandos no autorizados."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://www.facebook.com/security/advisories/cve-2024-49400","source":"cve-assign@fb.com"}]}}]}