CVE-2019-12997: Icon Loopchain

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment (aka injection in the DEFAULT_SCORE_HOST environment variable).

Affected products

  • Icon Loopchain: up to and including 2.2.1.3

Published 2019-06-28. Last modified 2026-06-17.