Gerapy is a web-based distributed web scraping and crawling platform that presents a narrowly scoped vulnerability footprint centered on its single core product. The durable signal reflects command-injection weaknesses—both OS command injection and general command injection—that arise from the platform's execution model and handling of user-supplied input in task configuration and orchestration contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gerapy over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43857HIGH Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8. | Dec 27, 2021 | 8.8 | 70 | NO | YES |
CVE-2021-32849HIGH Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There ar | Jan 26, 2022 | 8.8 | 32 | NO | NO |
CVE-2020-7698CRITICAL This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized. | Jul 29, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gerapy.
Media articles that mention a CVE ID that affects a product developed by Gerapy — matched by CVE ID, not by vendor name.