Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-21278

29
FAUCET Score

CVE-2021-21278 describes a critical code injection vulnerability in RSSHub, an open-source RSS feed generator, affecting versions prior to 7f1c430. The flaw stems from the use of 'eval' or 'Function constructor' in certain routes, allowing malicious target sites to inject and execute arbitrary code on the server. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a severe risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2021-01-25CPE matchmatch criteria
cpe:2.3:a:rsshub:rsshub:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.57%
Probability of exploitation in next 30 days
EPSS Percentile
72.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0157 is in the 60th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-pgjj-866w-fc5chigh

Risk of code injection

Oct 12, 2021

References

github.com / DIYgod/RSSHub/commit/7f1c43094e8a82e4d8f036ff7d42568fed00699d
PatchThird Party Advisory
github.com / DIYgod/RSSHub/security/advisories/GHSA-pgjj-866w-fc5c
Third Party Advisory
npmjs.com / package/rsshub
ProductThird Party Advisory