CVE-2021-23422
HIGHbikeshed < 3.0.0 - OS Command Injection via Inline Tag Command Metadata
Title source: llmDescription
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cb6b2dd
Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537646
Scores
CVSS v3
7.8
EPSS
0.0079
EPSS Percentile
51.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
bikeshed_project/bikeshed
< 3.0.0
pypi/bikeshed
0 - 3.0.0PyPI
Published
Aug 16, 2021
Tracked Since
Feb 18, 2026