CVE-2026-68489: WebPros Plesk Extension Node.js Toolkit
High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Affected products
- WebPros Plesk Extension Node.js Toolkit: before 2.5.0 (fixed in 2.5.0)
- WebPros Plesk Extension Ruby: before 1.6.6 (fixed in 1.6.6)
Published 2026-09-14. Last modified 2026-09-18.