PT-2020-14329 · Lookatme · Lookatme
D0C-S4Vage
·
Published
2020-10-26
·
Updated
2020-11-13
·
CVE-2020-15271
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
lookatme versions prior to 2.3.0
Description
The issue affects users who render untrusted markdown with lookatme, potentially allowing malicious shell commands to be automatically run on their system. This is due to the automatic loading of the built-in "terminal" and "file loader" extensions in affected versions.
Recommendations
For versions prior to 2.3.0, upgrade to version 2.3.0 or above.
As a temporary workaround, consider manually deleting the
lookatme/contrib/terminal.py and lookatme/contrib/file loader.py files.
It is also recommended to be aware of what is being rendered with lookatme to minimize potential risks.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lookatme