CVE-2019-19609
HIGH 9.0EPSS 54.1%
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 54.08% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2019-12-05
- Updated
- 2024-08-05
Proof-of-concept exploits (12)
- http://packetstormsecurity.com/files/163940/Strapi-3.0.0-beta.17.7-Remote-Code-Execution.…
- http://packetstormsecurity.com/files/163950/Strapi-CMS-3.0.0-beta.17.4-Remote-Code-Execut…
- D3m0nicw0lf/CVE-2019-196090★ · 2021-09-11
- Hackhoven/Strapi-RCE0★ · 2024-07-01
- RamPanic/CVE-2019-19609-EXPLOIT0★ · 2021-12-08
- abelsrzz/CVE-2019-18818_CVE-2019-196090★ · 2025-02-16
- diego-tella/CVE-2019-19609-EXPLOIT9★ · 2021-08-30
- ebadfd/CVE-2019-196097★ · 2021-08-29
- glowbase/CVE-2019-196092★ · 2022-01-25
- guglia001/CVE-2019-196090★ · 2021-08-30
- n000xy/CVE-2019-19609-POC-Python0★ · 2021-11-27
- z9fr/CVE-2019-196097★ · 2021-08-29