CVE-2017-1000212 describes a critical remote code execution vulnerability in Elixir's alchemist.vim plugin, specifically affecting the bundled alchemist-server and alchemist_elixir. A malicious website can exploit this by sending requests to an ephemeral localhost port, leading to arbitrary Elixir code execution. With a CVSS score of 9.8 (CRITICAL) and an attack vector of Network with low complexity and no user interaction, this flaw allows for complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation is reported, and community discussion is minimal, its high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:alchemist-elixir:alchemist-server:-:*:*:*:*:vim:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.