Vulnerability record · CVE-2021-42342 · published 14 October 2021
CVE-2021-42342: GoAhead file upload filter allows environment variable injection into CGI scripts
Embedthis · Goahead
GoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment variables reach CGI scripts. This breaks the boundary between user input and the CGI environment, so any CGI script that trusts those variables can be manipulated. The flaw is remotely reachable and rated critical by CVSS.
Description
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a very high EPSS score, makes this a top remediation target despite no KEV listing.
What it is
GoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment variables reach CGI scripts. This breaks the boundary between user input and the CGI environment, so any CGI script that trusts those variables can be manipulated. The flaw is remotely reachable and rated critical by CVSS.
Impact
An attacker can inject arbitrary environment variables into CGI scripts, which can lead to code execution or full compromise of the web server process depending on what the CGI scripts do with those variables. The CVSS vector indicates high confidentiality, integrity and availability impact.
Attack surface
Reached over the network through the file upload filter; the CVSS vector shows no privileges and no user interaction required. Any deployment exposing GoAhead with CGI scripts is potentially in scope.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is 0.5946 (99th percentile), indicating a high likelihood of exploitation activity.
What to do
- Upgrade GoAhead to 5.1.5 or later, which fixes the file upload filter prefix handling.
- If immediate upgrade is not possible, disable or restrict the file upload filter and CGI script execution on internet-facing instances.
- Audit CGI scripts for reliance on environment variables and validate or ignore unexpected variables.
- Place GoAhead behind a reverse proxy or WAF that filters multipart uploads and suspicious form field names.
- Monitor vendor advisories for backports if you run an embedded GoAhead build.
Detection
- Inspect HTTP multipart upload requests for form field names that do not carry the expected CGI prefix.
- Monitor CGI process environments for unexpected or attacker-controlled variable names.
- Review web server logs for anomalous upload requests followed by CGI execution or error spikes.
- Alert on GoAhead versions below 5.1.5 in asset inventories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/embedthis/goahead/issues/305 | Third Party Advisory |
| https://github.com/embedthis/goahead/issues/305 | Third Party Advisory |
Track CVE-2021-42342 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42342), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.