Description
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.
Exploits (1)
metasploit
WORKING POC
GREAT
by h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/pihole_remove_commands_lpe.rb
References (3)
Scores
CVSS v3
6.3
EPSS
0.1136
EPSS Percentile
93.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Details
CWE
CWE-269
CWE-78
Status
published
Products (2)
pi-hole/pi-hole
< 5.2.4
pi-hole/pi-hole
<= 5.2.4
Published
Apr 14, 2021
Tracked Since
Feb 18, 2026