CVE-2023-47105
Chaosblade vulnerable to OS command execution
Record summary
EIP currently links 1 Nuclei template to CVE-2023-47105.
Description
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ChaosbladeBrowse Chaosblade / ChaosbladeDefault status: unknown | VulnCheck, CVE List | 0.3 to ≤ 1.7.3 | affected |
github.com/chaosblade-io/chaosbladeBrowse Go / github.com/chaosblade-io/chaosblade | GitHub Advisory | 0.0.3 to < 1.7.4 · Fixed in 1.7.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHChaosblade < 1.7.4 - Remote Code ExecutionCVSS 8.6
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
Impact
This vulnerability allows unauthenticated attackers to remotely invoke the HTTP service and execute arbitrary commands on any Chaosblade instance with server mode enabled. This could lead to unauthorized access and control over the host system running Chaosblade.
Remediation
Fixed in 1.7.4
Source: ProjectDiscovery