CVE-2023-28627

HIGH

pymedusa <1.0.12 - Command Injection

Title source: llm
STIX 2.1

Description

pymedusa is an automatic video library manager for TV Shows. In versions prior 1.0.12 an attacker with access to the web interface can update the git executable path in /config/general/ > advanced settings with arbitrary OS commands. An attacker may exploit this vulnerability to take execute arbitrary OS commands as the user running the pymedusa program. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 8.3
EPSS 0.0081
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
pymedusa/medusa < 1.0.12
Published Mar 27, 2023
Tracked Since Feb 18, 2026