CVE-2021-23422

HIGH

bikeshed < 3.0.0 - OS Command Injection via Inline Tag Command Metadata

Title source: llm
STIX 2.1

Description

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

References (2)

Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537646

Scores

CVSS v3 7.8
EPSS 0.0079
EPSS Percentile 51.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
bikeshed_project/bikeshed < 3.0.0
pypi/bikeshed 0 - 3.0.0PyPI
Published Aug 16, 2021
Tracked Since Feb 18, 2026