# Qinglong Task Scheduler Auth Bypass Chain to RCE (CVE-2026-3965, CVE-2026-4047) — .fullgc Cryptomining Campaign

> An unidentified threat actor is chaining two unauthenticated authentication bypass vulnerabilities in the Qinglong open-source task scheduler (@whyour/qinglong, versions ≤ 2.20.1) to take over publicly exposed developer panels and deploy a multi-architecture cryptominer named .fullgc. CVE-2026-3965 (CWE-94, CVSS 9.3) abuses an Express.js URL rewrite that maps /open/* to /api/$1, exposing protected admin endpoints; CVE-2026-4047 (CWE-178, CVSS 9.3) bypasses the auth middleware via case-sensitivity mismatch (/aPi/...) so any privileged route can be reached unauthenticated. In-the-wild exploitation has been observed since 2026-02-07, with payloads served from file.551911.xyz to /ql/data/db/.fullgc on Linux x86_64, ARM64, and macOS.

- **Published:** 2026-05-01T00:36:43Z
- **Last reviewed:** 2026-05-01T00:36:43Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0441
- **ID:** TL-2026-0441
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3965, CVE-2026-4047

## Description

The Qinglong Task Scheduler (@whyour/qinglong on npm; ~19k GitHub stars, ~3.2k forks) is a popular Node.js task automation panel used heavily by developers — particularly in the Chinese-language community — to run scheduled scripts. In early February 2026, Qinglong users began reporting a hidden process named .fullgc consuming 85-100% CPU on their hosts. The process name imitates Java's "Full GC" garbage collection logs to evade casual inspection.

Investigation by Snyk (disclosed 2026-02-26 and 2026-02-27, published 2026-03-12) identified two distinct authentication bypass primitives that together allow an unauthenticated remote attacker to achieve RCE on any Internet-exposed Qinglong instance running version 2.20.1 or older.

CVE-2026-3965 (CWE-94, Improper Control of Generation of Code, CVSS 9.3): Qinglong configures Express.js middleware that rewrites incoming /open/* requests to /api/$1 to expose a small set of public endpoints. The rewrite is performed BEFORE the authentication middleware decides whether the request is privileged, so the security middleware sees an /open/ path (treated as public) while the router resolves to a fully privileged /api/ endpoint. An attacker can therefore call PUT /open/user/init with a JSON body containing a new admin username/password and the panel will reinitialize its credentials, granting full administrative control. From the panel an attacker can register and execute arbitrary scripts.

CVE-2026-4047 (CWE-178, Improper Handling of Case Sensitivity, CVSS 9.3): The authentication middleware checks req.path.startsWith('/api/') in case-sensitive fashion, while the Express.js router matches routes case-insensitively on the same paths. By requesting /aPi/system/command-run (or any other capitalization variant) an attacker bypasses the middleware entirely and reaches the command execution endpoint with no authentication. A single PUT to /aPi/system/command-run with a JSON {"command":"..."} body executes shell commands on the host.

In the observed campaign, the attacker chains either bypass to inject into Qinglong's config.sh, which is executed by the panel on schedule. The injected payload uses uname to detect platform and architecture and downloads a matching cryptominer binary from https://file.551911.xyz/fullgc/$(uname -s)_$(uname -m), saving it to /ql/data/db/.fullgc, chmod +x'ing it, and running it via nohup so it survives session exit. Binaries are provided for Linux x86_64, Linux ARM64 (aarch64), and macOS variants. The miner contains persistence logic that restarts itself if killed.

Qinglong maintainers initially responded with PR #2924, attempting to block command-injection patterns (curl, wget, shell metacharacters) at an input-validation layer — a mitigation that did not fix the underlying auth bypass. The effective patch landed in PR #2941 (commit 6bec52dca158481258315ba0fc2f11206df7b719 / ce599d306f81e3ebb0f6eaa5b540d701a6d4085d), shipped in @whyour/qinglong 2.20.2-0. Many Internet-exposed instances likely remain unpatched given Qinglong's distribution as a self-hosted Docker/npm app and the gap between exploitation (2026-02-07) and effective fix release.

No formal threat-actor attribution exists. The infrastructure (.xyz domain, multi-architecture cryptominer, no espionage tooling) and target (Chinese-language developer community running Qinglong) are consistent with an opportunistic financially-motivated cryptojacking operator rather than an APT.

## MITRE ATT&CK

- T1595 Active Scanning
- T1596 Search Open Technical Databases
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1546 Event Triggered Execution
- T1053 Scheduled Task/Job
- T1564 Hide Artifacts
- T1036 Masquerading
- T1070 Indicator Removal
- T1555 Credentials from Password Stores
- T1606 Forge Web Credentials
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1496 Resource Hijacking

## Sources

- [Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining](https://www.bleepingcomputer.com/news/security/hackers-exploit-rce-flaws-in-qinglong-task-scheduler-for-cryptomining/)
- [Qinglong RCE Flaws Exploited for Cryptomining](https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/)
- [Snyk Advisory CVE-2026-3965 — Remote Code Execution in @whyour/qinglong](https://security.snyk.io/vuln/SNYK-JS-WHYOURQINGLONG-15440732)
- [Snyk Advisory CVE-2026-4047 — Improper Handling of Case Sensitivity in @whyour/qinglong](https://security.snyk.io/vuln/SNYK-JS-WHYOURQINGLONG-15468374)
- [GitLab Advisory CVE-2026-3965](https://advisories.gitlab.com/pkg/npm/@whyour/qinglong/CVE-2026-3965/)
- [Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild](https://cybersecuritynews.com/qinglong-task-scheduler-rce-vulnerabilities/)
- [Qinglong Task Scheduler RCE Flaws Exploited in the Wild](https://gbhackers.com/qinglong-task-scheduler-rce-flaws/)
- [Qinglong Vulnerabilities Enable RCE, Exploited in Attacks](https://cyberpress.org/qinglong-task-scheduler-rce-flaws/)
- [Qinglong PR #2941 — auth middleware fix](https://github.com/whyour/qinglong/pull/2941)
- [Qinglong Issue #2934 — case-sensitivity bypass report](https://github.com/whyour/qinglong/issues/2934)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0441
