Vulnerability record · CVE-2020-11108 · published 11 May 2020
CVE-2020-11108: Pi-hole Gravity updater unrestricted file upload leads to RCE
Pi Hole · Pi Hole
The Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user upload arbitrary files. Because the web directory is writable, an attacker can drop a PHP file and execute code, and the flaw can be chained with the www-data sudo rule to reach root.
Description
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote code execution with root escalation potential, and public exploit code plus a very high EPSS score make exploitation likely despite no KEV listing.
What it is
The Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user upload arbitrary files. Because the web directory is writable, an attacker can drop a PHP file and execute code, and the flaw can be chained with the www-data sudo rule to reach root.
Impact
An authenticated attacker gains remote code execution as the web server user and can escalate to root, giving full control of the Pi-hole host.
Attack surface
Reached over the network through the Pi-hole web interface and Gravity update functionality; the CVSS vector shows PR:L, so a low-privileged authenticated account is required, and no user interaction is needed.
Exploitation
Public exploit code and write-ups are referenced, and EPSS is very high at 0.78262 (99.5th percentile), but the CVE is not listed in CISA KEV.
What to do
- Upgrade Pi-hole to a version after 4.4 that fixes gravity_DownloadBlocklistFromUrl in gravity.sh.
- Restrict access to the Pi-hole web interface and admin accounts to trusted networks and users.
- Remove or tightly scope the sudo rule granted to the www-data user to block privilege escalation to root.
- Ensure the web directory is not writable by the web server process where possible.
Detection
- Monitor the Pi-hole web directory for newly created or modified PHP files.
- Alert on unexpected outbound downloads or blocklist fetches initiated by the Gravity updater.
- Audit sudo usage by the www-data user for anomalous or unexpected commands.
- Review web server logs for POST requests to Gravity or admin endpoints followed by PHP execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11108 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.