CVE-2020-36911

CRITICAL

Covenant 0.1.3-0.5 - RCE

Title source: llm

Description

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Exploits (1)

exploitdb WORKING POC
by xThaz · pythonwebappsmultiple
https://www.exploit-db.com/exploits/51141

Scores

CVSS v3 9.8
EPSS 0.0086
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
cobbr/covenant 0.1.3 - 0.5
Published Jan 13, 2026
Tracked Since Feb 18, 2026