← Vulnerability feed

Vulnerability record · CVE-2016-5713 · published 6 December 2017

CVE-2016-5713: Puppet agent code injection vulnerability

Puppet · Puppet Agent

Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.

9.8 CVSS 3.0 Critical EPSS 2.0% · top 19.8% CWE-94 · Code injection
9.8CVSS 3.0 base score, v2 7.5
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-5713 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27023Puppet agent vulnerabilityA flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…EPSS 1.4%9.8CVE-2016-2786Puppet agent improper input validation vulnerabilityThe pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…EPSS 1.6%9.8CVE-2016-2785Puppet improper access control vulnerabilityPuppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass i…EPSS 2.9%7.2CVE-2016-5714Puppet enterprise improper access control vulnerabilityPuppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect…EPSS 2.2%6.5CVE-2021-27025Puppet vulnerabilityA flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior…EPSS 1.2%6.5CVE-2020-7942Puppet improper certificate validation vulnerabilityPreviously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised cert…EPSS 0.82%5.9CVE-2015-1855Ruby-lang ruby improper input validation vulnerabilityverify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properl…EPSS 2.8%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2016-5713), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.