Impact
Static Code Injection in Plesk extensions "Ruby" and "Node.js Toolkit" allows a remote authenticated user to inject code into the execution environment. By setting custom environment variables, the attacker can cause the vulnerable helper process to interpret untrusted input as code. The result is arbitrary code execution running with root privileges on the host system, which can lead to full system compromise, data exfiltration, or persistence mechanisms.
Affected Systems
The vulnerability affects the WebPros Plesk extensions "Ruby" versions prior to 1.6.6 and "Node.js Toolkit" versions prior to 2.5.0. No other vendors or products are listed in the CNA data. Users deploying these extensions on a Plesk server are at risk unless the extensions are updated.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is unavailable, but the lack of a KEV listing does not mitigate the risk; exploit code could still be crafted by attackers with authenticated access. The attack vector is inferred to be a remote authenticated user who can set environment variables within the context of the Plesk server, a common user role for administrators or plugin owners. The attacker’s ability to execute code as root makes exploitation extremely damaging.
OpenCVE Enrichment