CVE-2023-38942

CRITICAL

dango-translator 4.5.5 - Remote Code Execution via Cloud Config JSON

Title source: llm
STIX 2.1

Description

Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory
https://github.com/PantsuDango/Dango-Translator/issues/127

Scores

CVSS v3 9.8
EPSS 0.0165
EPSS Percentile 73.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
dango/dango-translator 4.5.5
Published Aug 03, 2023
Tracked Since Feb 18, 2026