Record summary

EIP currently links 1 Nuclei template to CVE-2023-47105.

Description

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE List0.3 to ≤ 1.7.3affected

github.com/chaosblade-io/chaosblade

Browse Go / github.com/chaosblade-io/chaosblade
GitHub Advisory0.0.3 to < 1.7.4 · Fixed in 1.7.4affected

Nuclei templates

1
ProjectDiscoveryHIGHChaosblade < 1.7.4 - Remote Code ExecutionCVSS 8.6

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.

Impact

This vulnerability allows unauthenticated attackers to remotely invoke the HTTP service and execute arbitrary commands on any Chaosblade instance with server mode enabled. This could lead to unauthorized access and control over the host system running Chaosblade.

Remediation

Fixed in 1.7.4

WeaknessesCWE-78
Authorss4e-io
Template tagscvecve2023chaosbladercevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Source: ProjectDiscovery

References

6