CVE-2024-36360 is a critical OS command injection vulnerability affecting awkblog v0.0.1 and earlier versions. An unauthenticated attacker can exploit this by sending a specially crafted HTTP request, leading to arbitrary OS command execution with the privileges of the affected product. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and there is minimal community discussion or media coverage, suggesting it is not actively exploited in the wild at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Keisuke Nakayama | Awkblog | v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlierCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.