Vendor Homepageproduct
https://cobbr.io/Covenant.html CVE-2020-36911
CRITICAL
Covenant 0.5 - Remote Code Execution (RCE)
Record summary
CVE-2020-36911 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CovenantBrowse Cobbr / Covenant | CVE List | 0.1.3 to ≤ 0.5 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCovenant v0.5 - Remote Code Execution (RCE)ExploitDB exploitby xThazNot analyzed1 file
References
8Exploit Repositoryexploit
https://github.com/Zeop-CyberSec/covenant_rce/blob/master/covenant_jwt_rce.rb Covenant GitHub Repositoryproduct
https://github.com/cobbr/Covenant nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36911 Archived Maintainer Patch AnnouncementVendor advisorypatch
https://web.archive.org/web/20201013165001/https://twitter.com/cobbr_io/status/1316058367161401344 Archived Researcher BlogTechnical descriptionexploit
https://web.archive.org/web/20201101052547/https://blog.null.farm/hunting-the-hunters ExploitDB-51141exploit
https://www.exploit-db.com/exploits/51141 VulnCheck Advisory: Covenant 0.5 - Remote Code Execution (RCE)Third-party advisory
https://www.vulncheck.com/advisories/covenant-remote-code-execution-rce