7.8
CVSSv3

CVE-2021-30005

Published: 11/05/2021 Updated: 12/07/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In JetBrains PyCharm prior to 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jetbrains pycharm

Github Repositories

CVE-2021-30005-POC PoC for CVE-2021-30005 Details The vulnerability resides in the fact that PyCharm would automatically activate a virtual environment found in the project when opened for the first time This allowed an attacker to create a repository containing a malicious virtual environment with arbitrary commands in the activation scripts (eg venv/bin/activate), that wo