Vulnerability record · CVE-2021-43857 · published 27 December 2021
CVE-2021-43857: Gerapy OS command injection enables remote code execution
Gerapy · Gerapy
Gerapy, a distributed crawler management framework, is vulnerable to remote code execution in versions prior to 0.9.8. The flaw is classified as OS command injection (CWE-78), and the vendor patched it in version 0.9.8. Because Gerapy is a management framework that runs crawler jobs, code execution on its host is a serious exposure.
Description
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a public exploit and very high EPSS, but exploitation requires low-privileged authenticated access and there is no KEV listing.
What it is
Gerapy, a distributed crawler management framework, is vulnerable to remote code execution in versions prior to 0.9.8. The flaw is classified as OS command injection (CWE-78), and the vendor patched it in version 0.9.8. Because Gerapy is a management framework that runs crawler jobs, code execution on its host is a serious exposure.
Impact
An attacker who can reach the vulnerable functionality gains remote code execution on the Gerapy host, with high impact to confidentiality, integrity and availability per the CVSS vector. This can lead to full compromise of the management server and any crawler infrastructure it controls.
Attack surface
The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), so the attacker needs some authenticated access to the application. The description does not specify the exact endpoint or parameter involved.
Exploitation
A public exploit exists (Packet Storm reference tagged Exploit), and EPSS is 0.55331 (99th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild evidence in this record.
What to do
- Upgrade Gerapy to version 0.9.8 or later, which contains the patch commit 49bcb19be5e0320e7e1535f34fe00f16a3cf3b28.
- Restrict network access to the Gerapy management interface to trusted hosts only.
- Enforce least privilege for Gerapy accounts and avoid granting access to untrusted users.
- Run Gerapy under a dedicated low-privilege service account to limit the impact of command execution.
Detection
- Monitor Gerapy host process creation for unexpected shell or command interpreter children spawned by the Gerapy service.
- Review Gerapy application and web server logs for suspicious requests to management endpoints, especially from unusual source addresses.
- Alert on outbound network connections from the Gerapy host that do not match normal crawler traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165459/Gerapy-0.9.7-Remote-Code-Execution.html | ExploitThird Party Advisory |
| https://github.com/Gerapy/Gerapy/commit/49bcb19be5e0320e7e1535f34fe00f16a3cf3b28 | PatchThird Party Advisory |
| https://github.com/Gerapy/Gerapy/issues/219 | Issue TrackingThird Party Advisory |
| https://github.com/Gerapy/Gerapy/security/advisories/GHSA-9w7f-m4j4-j3xw | Third Party Advisory |
| http://packetstormsecurity.com/files/165459/Gerapy-0.9.7-Remote-Code-Execution.html | ExploitThird Party Advisory |
| https://github.com/Gerapy/Gerapy/commit/49bcb19be5e0320e7e1535f34fe00f16a3cf3b28 | PatchThird Party Advisory |
| https://github.com/Gerapy/Gerapy/issues/219 | Issue TrackingThird Party Advisory |
| https://github.com/Gerapy/Gerapy/security/advisories/GHSA-9w7f-m4j4-j3xw | Third Party Advisory |
Track CVE-2021-43857 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-43857), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.