Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2448-826c-4v5m

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

EPSS

Процентиль: 29%
0.00105
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
22 дня назад

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

EPSS

Процентиль: 29%
0.00105
Низкий

8.8 High

CVSS3

Дефекты

CWE-94