Description
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Static Code Injection in Plesk extensions Ruby and Node.js Toolkit allows a remote authenticated user to inject code by setting custom environment variables. The vulnerable helper process interprets this untrusted input as code, enabling arbitrary code execution with root privileges on the host. This can lead to full system compromise, data exfiltration, or persistence mechanisms.

Affected Systems

The vulnerability affects the WebPros Plesk extensions Ruby for versions prior to 1.6.6 and Node.js Toolkit for versions prior to 2.5.0. No other vendors or products are listed. Users that deploy these extensions on a Plesk server are at risk unless the extensions are updated.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, but the EPSS score of less than 1 percent indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet it can still be leveraged by attackers who have authenticated access to the Plesk server. The likely attack vector is a remote authenticated user who can set custom environment variables for the extensions, a privilege typically granted to system administrators or plugin owners. If exploited, the attacker can execute arbitrary code with root privileges on the host, resulting in complete system compromise.

Generated by OpenCVE AI on September 17, 2026 at 19:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Plesk Ruby extension to version 1.6.6 or newer and the Node.js Toolkit extension to version 2.5.0 or newer.
  • Restrict or disable the ability to set custom environment variables for these extensions through server configuration or security policies.
  • Limit administrative privileges to trusted users and monitor for anomalous environment variable usage or unexpected code execution.

Generated by OpenCVE AI on September 17, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros plesk Extension "node.js Toolkit"
Webpros plesk Extension "ruby"
Vendors & Products Webpros
Webpros plesk Extension "node.js Toolkit"
Webpros plesk Extension "ruby"

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Ruby: Node.js Toolkit: Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection
Weaknesses CWE-94
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Weaknesses CWE-96
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Webpros Plesk Extension "node.js Toolkit" Plesk Extension "ruby"
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-15T13:28:53.581Z

Reserved: 2026-07-30T15:00:00.609Z

Link: CVE-2026-68489

cve-icon Vulnrichment

Updated: 2026-09-15T13:28:50.369Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:25.567

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-68489

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T20:53:05Z

Links: CVE-2026-68489 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')

  • CWE-96

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')