Emissary versions prior to 8.39.0 contain a command injection vulnerability in the Executrix utility class, which constructs shell commands by concatenating configuration-derived values with insufficient input sanitization. The flaw allows shell metacharacters to bypass filters that only replace spaces with underscores, enabling arbitrary command execution through the PLACE_NAME parameter. This vulnerability affects Emissary's P2P-based workflow engine across all affected versions until the 8.39.0 patch. The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring high-level privileges and no user interaction. Exploitation results in complete system compromise, including high-impact confidentiality, integrity, and availability breaches through direct shell command execution. The attack has low complexity, making it straightforward to exploit once an attacker gains privileged access to configure the affected parameter. There is no evidence of active exploitation in the wild, as indicated by the absence of KEV designation and inactive status on security hotlists. The EPSS score of 0.00087 suggests minimal real-world exploitation probability. However, organizations running Emissary versions before 8.39.0 should prioritize patching immediately, as the vulnerability is trivial to exploit for any authenticated administrator with configuration access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.38.0CPE matchmatch criteria | cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.