PT-2020-14329 · Lookatme · Lookatme

D0C-S4Vage

·

Published

2020-10-26

·

Updated

2020-11-13

·

CVE-2020-15271

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions lookatme versions prior to 2.3.0
Description The issue affects users who render untrusted markdown with lookatme, potentially allowing malicious shell commands to be automatically run on their system. This is due to the automatic loading of the built-in "terminal" and "file loader" extensions in affected versions.
Recommendations For versions prior to 2.3.0, upgrade to version 2.3.0 or above. As a temporary workaround, consider manually deleting the lookatme/contrib/terminal.py and lookatme/contrib/file loader.py files. It is also recommended to be aware of what is being rendered with lookatme to minimize potential risks.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15271
GHSA-C84H-W6CR-5V8Q
PYSEC-2020-61

Affected Products

Lookatme