CVE-2019-19609 EXPLOIT
7.2
HIGH · CVSS 3.1 · EPSS 54.1% (pctl 99)
Patch early
A public exploit exists.
Description
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
Scoring
| CVSS | 7.2 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 54.08% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-12-05 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| strapi | strapi |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated) | 2021-08-30 |
References
- http://packetstormsecurity.com/files/163940/Strapi-3.0.0-beta.17.7-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/163950/Strapi-CMS-3.0.0-beta.17.4-Remote-Code-Execution.html
- https://bittherapy.net/post/strapi-framework-remote-code-execution/
- https://github.com/strapi/strapi/pull/4636
- http://packetstormsecurity.com/files/163940/Strapi-3.0.0-beta.17.7-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/163950/Strapi-CMS-3.0.0-beta.17.4-Remote-Code-Execution.html
- https://bittherapy.net/post/strapi-framework-remote-code-execution/
- https://github.com/strapi/strapi/pull/4636
→ the Explorer · watch your stack · NVD