CVE-2020-7604: Pulverizr Project Pulverizr
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.
Affected products
- Pulverizr Project Pulverizr: up to and including 0.7.0
Published 2020-03-15. Last modified 2026-06-17.