CVE-2020-37027

CRITICAL

Sickbeard alpha - Command Injection

Title source: llm

Description

Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the extra scripts configuration. Attackers can set malicious commands in the extra scripts field and trigger processing to execute remote code on the vulnerable Sickbeard installation.

Exploits (1)

exploitdb WORKING POC
by bdrake · pythonwebappshardware
https://www.exploit-db.com/exploits/48646

Scores

CVSS v3 9.8
EPSS 0.0073
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Published Jan 30, 2026
Tracked Since Feb 18, 2026