CVE-2017-16020 describes a critical command injection vulnerability affecting Summit web framework versions 0.1.0 and later, specifically when utilizing the PouchDB driver. An unauthenticated attacker can achieve arbitrary command execution by manipulating the collection name. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion and media coverage are minimal, the potential impact remains extremely high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, <= 0.1.21CPE matchmatch criteria | cpe:2.3:a:summit_project:summit:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.