Skip to content

Improper Control of Generation of Code ('Code Injection') in tuxbot.cogs.Math

Moderate
Rom1-J published GHSA-2p24-qf2h-p7h7 Jun 9, 2021

Package

tuxbot.cogs.Math (Math cog)

Affected versions

<1.0.0

Patched versions

1.0.1

Description

Impact

Remote Code Execution within the command .graph

Patches

Patched in 385b6df

Workarounds

Unload the math module with .jsk unload tuxbot.cogs.Math or directly within the sources by add a comment in line 55 of tuxbot/core/bot.py

References

Join the GnousEU discord server

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

No known CVE

Weaknesses