← Vulnerability feed

Vulnerability record · CVE-2020-11108 · published 11 May 2020

CVE-2020-11108: Pi-hole Gravity updater unrestricted file upload leads to RCE

Pi Hole · Pi Hole

The Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user upload arbitrary files. Because the web directory is writable, an attacker can drop a PHP file and execute code, and the flaw can be chained with the www-data sudo rule to reach root.

8.8 CVSS 3.1 High EPSS 78% · top 0.4% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 9.0
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote code execution with root escalation potential, and public exploit code plus a very high EPSS score make exploitation likely despite no KEV listing.

What it is

The Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user upload arbitrary files. Because the web directory is writable, an attacker can drop a PHP file and execute code, and the flaw can be chained with the www-data sudo rule to reach root.

Impact

An authenticated attacker gains remote code execution as the web server user and can escalate to root, giving full control of the Pi-hole host.

Attack surface

Reached over the network through the Pi-hole web interface and Gravity update functionality; the CVSS vector shows PR:L, so a low-privileged authenticated account is required, and no user interaction is needed.

Exploitation

Public exploit code and write-ups are referenced, and EPSS is very high at 0.78262 (99.5th percentile), but the CVE is not listed in CISA KEV.

What to do

  • Upgrade Pi-hole to a version after 4.4 that fixes gravity_DownloadBlocklistFromUrl in gravity.sh.
  • Restrict access to the Pi-hole web interface and admin accounts to trusted networks and users.
  • Remove or tightly scope the sudo rule granted to the www-data user to block privilege escalation to root.
  • Ensure the web directory is not writable by the web server process where possible.

Detection

  • Monitor the Pi-hole web directory for newly created or modified PHP files.
  • Alert on unexpected outbound downloads or blocklist fetches initiated by the Gravity updater.
  • Audit sudo usage by the www-data user for anomalous or unexpected commands.
  • Review web server logs for POST requests to Gravity or admin endpoints followed by PHP execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11108 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2020-8816Pi-hole AdminLTE DHCP static lease OS command injectionPi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard u…KEVEPSS 78%analysed9.0CVE-2025-34087Pi-hole os command injection vulnerabilityAn authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, t…EPSS 7.0%8.8CVE-2026-50130Pi-hole vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with cod…EPSS 0.26%8.8CVE-2024-34361Pi-hole server-side request forgery (ssrf) vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior …EPSS 2.8%8.8CVE-2021-32706Pi-hole Web interface regex filter flaw enables code injectionPi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pa…EPSS 60%analysed8.8CVE-2021-29448Pi-hole ftldns cross-site scripting vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which ca…EPSS 0.67%8.8CVE-2019-13051Pi-hole os command injection vulnerabilityPi-Hole 4.3 allows Command Injection.EPSS 12%7.8CVE-2021-29449Pi-hole improper privilege management vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-11108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.