CVE-2016-10589 affects the spunjs selenium-binaries package, which insecurely downloads Selenium-related binaries over HTTP. This vulnerability allows for potential Man-in-the-Middle (MITM) attacks, where an attacker could swap legitimate binaries with malicious ones. With a CVSS score of 8.1 (High), this flaw presents a significant risk of remote code execution (RCE) with high impact on confidentiality, integrity, and availability, requiring high attack complexity but no user interaction. While the vulnerability is not listed on the KEV catalog and has no known public exploits or significant community discussion, its potential for RCE makes it a serious concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.10.0CPE matchmatch criteria | cpe:2.3:a:spunjs:selenium-binaries:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.