CVE-2021-43857

CRITICAL

Gerapy <0.9.8 - RCE

Title source: llm

Description

Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.

Exploits (6)

exploitdb WORKING POC
by Jeremiasz Pluta · pythonremotepython
https://www.exploit-db.com/exploits/50640
nomisec WORKING POC 1 stars
by lowkey0808 · poc
https://github.com/lowkey0808/CVE-2021-43857
nomisec WORKING POC
by afifudinmtop · poc
https://github.com/afifudinmtop/CVE-2021-43857-Gerapy-v0.9.7
nomisec WORKING POC
by ProwlSec · poc
https://github.com/ProwlSec/gerapy-cve-2021-43857
nomisec WORKING POC
by G4sp4rCS · poc
https://github.com/G4sp4rCS/CVE-2021-43857-POC
inthewild WORKING POC
poc
https://github.com/longwayhomie/cve-2021-43857

Scores

CVSS v3 9.8
EPSS 0.4964
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
gerapy/gerapy < 0.9.8
pypi/gerapy 0 - 0.9.8PyPI
Published Dec 27, 2021
Tracked Since Feb 18, 2026