Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23420

29
FAUCET Score

CVE-2021-23420 is a critical deserialization vulnerability affecting codeception/codeception versions 4.0.0 through 4.1.21 and versions before 3.1.3. An unauthenticated attacker can exploit this by sending specially crafted serialized user input, allowing arbitrary command execution on the vulnerable system. With a CVSS score of 9.8, this vulnerability poses a severe risk of complete compromise (confidentiality, integrity, and availability). While no active exploitation or public exploit code has been identified, and community discussion is minimal, its critical nature warrants immediate patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.1.3CPE matchmatch criteria
cpe:2.3:a:codeception:codeception:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.1.22CPE matchmatch criteria
cpe:2.3:a:codeception:codeception:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.71%
Probability of exploitation in next 30 days
EPSS Percentile
84.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0271 is in the 75th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: codeception/codeceptionFixed in: 4.1.22
composerpatch availablevia ghsa
Product: codeception/codeceptionFixed in: 3.1.3
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-4574-qv3w-fcmgcritical

Deserialization of Untrusted Data in codeception/codeception

Sep 1, 2021

References

github.com / Codeception/Codeception/blob/4.1/ext/RunProcess.php%23L52
Broken Link
github.com / Codeception/Codeception/pull/6241
PatchThird Party Advisory
github.com / JinYiTong/poc
ExploitThird Party Advisory
snyk.io / vuln/SNYK-PHP-CODECEPTIONCODECEPTION-1324585
Third Party Advisory