Impact
Static Code Injection in Plesk extensions Ruby and Node.js Toolkit allows a remote authenticated user to inject code by setting custom environment variables. The vulnerable helper process interprets this untrusted input as code, enabling arbitrary code execution with root privileges on the host. This can lead to full system compromise, data exfiltration, or persistence mechanisms.
Affected Systems
The vulnerability affects the WebPros Plesk extensions Ruby for versions prior to 1.6.6 and Node.js Toolkit for versions prior to 2.5.0. No other vendors or products are listed. Users that deploy these extensions on a Plesk server are at risk unless the extensions are updated.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, but the EPSS score of less than 1 percent indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet it can still be leveraged by attackers who have authenticated access to the Plesk server. The likely attack vector is a remote authenticated user who can set custom environment variables for the extensions, a privilege typically granted to system administrators or plugin owners. If exploited, the attacker can execute arbitrary code with root privileges on the host, resulting in complete system compromise.
OpenCVE Enrichment