Vulnerability record · CVE-2020-35131 · published 8 January 2021
CVE-2020-35131: Cockpit PHP code injection in MongoLite Database leads to RCE
Agentejo · Cockpit
Cockpit before 0.6.1 passes attacker-controlled JSON values into registerCriteriaFunction in lib/MongoLite/Database.php, allowing injection of custom PHP code. Because the injected code executes on the server, this is a full remote command execution flaw in an unauthenticated web-reachable component.
Description
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable PHP code injection with a public exploit and very high EPSS score warrants immediate patching.
What it is
Cockpit before 0.6.1 passes attacker-controlled JSON values into registerCriteriaFunction in lib/MongoLite/Database.php, allowing injection of custom PHP code. Because the injected code executes on the server, this is a full remote command execution flaw in an unauthenticated web-reachable component.
Impact
An attacker can execute arbitrary PHP and operating system commands on the Cockpit host, leading to full server compromise and access to data and credentials handled by the application.
Attack surface
Reachable over the network through the /auth/check or /auth/requestreset URIs by supplying crafted JSON data; the CVSS vector indicates no privileges or user interaction are required.
Exploitation
A public Exploit-DB entry (49390) exists, and EPSS is 0.51299 (98.9th percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.
What to do
- Upgrade Cockpit to 0.6.1 or later, which contains the fix in lib/MongoLite/Database.php.
- If immediate upgrade is not possible, restrict network access to /auth/check and /auth/requestreset and to the Cockpit instance generally.
- Review and harden any custom code paths that pass user-supplied JSON into MongoLite query criteria functions.
- Run the Cockpit service with least privilege and in a segregated environment to limit post-exploitation reach.
Detection
- Inspect web logs for POST requests to /auth/check or /auth/requestreset containing PHP code or unusual JSON structures.
- Monitor for unexpected PHP process execution or child processes spawned by the web server.
- Look for newly written or modified PHP files under the Cockpit webroot that were not part of a deployment.
- Alert on outbound network connections from the Cockpit host that are inconsistent with normal application behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/agentejo/cockpit/commits/next/lib/MongoLite/Database.php | Third Party Advisory |
| https://github.com/agentejo/cockpit/releases/tag/0.6.1 | Release NotesThird Party Advisory |
| https://www.exploit-db.com/exploits/49390 | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/agentejo/cockpit/commits/next/lib/MongoLite/Database.php | Third Party Advisory |
| https://github.com/agentejo/cockpit/releases/tag/0.6.1 | Release NotesThird Party Advisory |
| https://www.exploit-db.com/exploits/49390 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2020-35131 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35131), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.