Impact
The vulnerability resides in the executeCommand function within the Administrative Console of diem. By supplying a crafted dm_command value, an attacker can inject arbitrary operating‑system commands, leading to execution outside the intended scope. The flaw permits remote exploitation with no local privilege requirement, and an exploit is publicly available.
Affected Systems
The affected product is diem issued by diem-project. Versions up to and including 5.1.3 are vulnerable. No other impacted products are listed.
Risk and Exploitability
The CVSS base score of 5.1 denotes medium severity. The EPSS score is not available, but the vulnerability is not in the CISA KEV list. The attack vector is remote, with the error being uncovered in a public repository, suggesting that attackers could target exposed instances. The risk remains moderate unless mitigated by disabling the vulnerable function or restricting console access.
OpenCVE Enrichment