CVE-2019-25441

CRITICAL

thesystem 1.0 - Command Injection

Title source: llm

Description

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on the server without authentication.

Exploits (1)

exploitdb WORKING POC
by Sadik Cetin · textwebappspython
https://www.exploit-db.com/exploits/47441

Scores

CVSS v3 9.8
EPSS 0.0343
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
kostasmitroglou/thesystem 1.0.0
kostasmitroglou/thesystem 1.0
Published Feb 20, 2026
Tracked Since Feb 21, 2026