CVE-2019-19609 describes a Remote Code Execution (RCE) vulnerability in the Strapi framework prior to version 3.0.0-beta.17.8. This flaw allows authenticated attackers to inject arbitrary shell commands through unsanitized plugin names within the Admin panel's Install and Uninstall Plugin components. With a CVSS score of 7.2 (High) and a FAUCET Risk Score of 99/100, this vulnerability presents a significant threat, enabling full compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, an authenticated RCE exploit is publicly available on ExploitDB, and there is some community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.4CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:3.0.0:alpha10.1:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:3.0.0:alpha10.2:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:3.0.0:alpha10.3:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:3.0.0:alpha11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.