CVE-2021-43857
CRITICALGerapy <0.9.8 - RCE
Title source: llmDescription
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
Exploits (6)
exploitdb
WORKING POC
by Jeremiasz Pluta · pythonremotepython
https://www.exploit-db.com/exploits/50640
nomisec
WORKING POC
by afifudinmtop · poc
https://github.com/afifudinmtop/CVE-2021-43857-Gerapy-v0.9.7
References (4)
Scores
CVSS v3
9.8
EPSS
0.4964
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
gerapy/gerapy
< 0.9.8
pypi/gerapy
0 - 0.9.8PyPI
Published
Dec 27, 2021
Tracked Since
Feb 18, 2026