CVE-2023-30621 is a critical arbitrary command injection vulnerability affecting the Gipsy Discord bot in versions prior to 1.3. The flaw allows unauthenticated attackers to execute commands on the host machine with root privileges via the !ping command, due to insufficient input validation. With a CVSS score of 9.8, this vulnerability poses a severe risk of complete compromise (confidentiality, integrity, and availability). While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating potential interest from threat actors. Users are strongly advised to upgrade immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3CPE matchmatch criteria | cpe:2.3:a:gipsy_project:gipsy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.