← Vulnerability feed

Vulnerability record · CVE-2019-19609 · published 5 December 2019

CVE-2019-19609: Strapi Admin panel plugin name command injection RCE

Strapi · Strapi

Strapi before 3.0.0-beta.17.8 fails to sanitize the plugin name in the Admin panel Install and Uninstall Plugin components, allowing shell command injection into the execa call. An authenticated admin can execute arbitrary commands on the server, turning a content management interface into a remote code execution path.

7.2 CVSS 3.1 High EPSS 54% · top 1.0% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with a public exploit and very high EPSS, but it requires an authenticated admin account, which limits exposure.

What it is

Strapi before 3.0.0-beta.17.8 fails to sanitize the plugin name in the Admin panel Install and Uninstall Plugin components, allowing shell command injection into the execa call. An authenticated admin can execute arbitrary commands on the server, turning a content management interface into a remote code execution path.

Impact

An attacker with Admin panel access gains arbitrary command execution on the host running Strapi, enabling data theft, persistence or full server compromise.

Attack surface

Reached over the network through the Strapi Admin panel plugin install/uninstall functionality. The CVSS vector requires high privileges (PR:H) and no user interaction, so a valid admin-level account is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.54081 (99th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.

What to do

  • Upgrade Strapi to 3.0.0-beta.17.8 or later, which includes the fix in PR 4636.
  • If immediate upgrade is not possible, restrict Admin panel access to trusted networks and disable plugin install/uninstall where feasible.
  • Enforce least privilege on Strapi admin accounts and audit who holds admin roles.
  • Monitor and rotate credentials for any admin account that may have been exposed.
  • Review server logs for unexpected child processes spawned by the Strapi Node.js process.

Detection

  • Alert on Strapi admin API calls to plugin install/uninstall endpoints, especially with shell metacharacters in the plugin name.
  • Monitor for child processes (sh, bash, curl, wget) spawned by the Node.js/Strapi process.
  • Search application and system logs for command strings or outbound connections originating from the Strapi host after admin plugin actions.
  • Baseline normal admin plugin activity and flag installs of unknown or unexpected plugins.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19609 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38507Strapi allocation without limits vulnerabilityStrapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's adm…EPSS 0.96%9.8CVE-2022-27263Strapi unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.EPSS 3.2%9.8CVE-2020-27664Strapi vulnerabilityadmin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.EPSS 2.3%9.8CVE-2019-18818Strapi password reset mishandling enables account takeoverStrapi before 3.0.0-beta.17.5 mishandles password resets in the admin and users-permissions Auth controllers. The flaw is classified as CWE-640 (weak…EPSS 98%analysed9.3CVE-2026-22599Strapi sql injection vulnerabilityStrapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a d…EPSS 1.2%9.2CVE-2026-27886Strapi path traversal vulnerabilityStrapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer…EPSS 2.5%8.8CVE-2022-31367Strapi sql injection vulnerabilityStrapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.EPSS 1.7%8.8CVE-2022-32114Strapi unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF f…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2019-19609), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.