Impact
A flaw in Cockpit CMS versions before 2.14.0 permits an attacker to inject code through the filter parameter of several endpoints. The injected value is evaluated by the MongoLite database using the $func operator, which can invoke arbitrary system commands. This vulnerability leads directly to uncontrolled code execution on the underlying host, exposing the full confidentiality, integrity, and availability of the server. The weakness aligns with command and code injection issues such as CWE‑94.
Affected Systems
The security issue affects Cockpit CMS releases 2.13.5 and earlier. Any installation running those versions exposes the vulnerable endpoints. The official advisory lists the affected release as 2.13.5 and the new release 2.14.0 that includes the fix.
Risk and Exploitability
With a CVSS score of 9.8 and an EPSS score of < 1%, the vulnerability is rated as critical, but the low exploitation probability indicates that active exploitation is currently rare. However, because the flaw allows arbitrary command execution and is exposed over network endpoints, it remains a high‑risk issue for any organization that runs affected versions. The lack of KEV listing does not reduce the urgency, as the flaw is clearly exploitable regardless of current exploit availability.
OpenCVE Enrichment
Github GHSA