CVE-2018-15747: Glot Glot-Www

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system within a "python" "files" "content" JSON file.

Affected products

  • Glot Glot-Www: up to and including 2018-05-19

Published 2019-06-21. Last modified 2026-06-17.