Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmpq-66cp-597x

Опубликовано: 26 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

EPSS

Процентиль: 21%
0.00067
Низкий

8.8 High

CVSS3

Дефекты

CWE-272

Связанные уязвимости

CVSS3: 8.8
nvd
13 дней назад

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

EPSS

Процентиль: 21%
0.00067
Низкий

8.8 High

CVSS3

Дефекты

CWE-272