← Back to browse · API

CVE-2020-29007

Severity
CRITICAL
CVSS
9.8
EPSS
0.02317
Risk score
40.01
CISA KEV
No
PoC
No
Published
2023-04-15
Modified
2025-02-06
First seen
2026-08-07
Aliases
EUVD-2020-21389, GHSA-V67W-WJQM-H9PJ
Products
n/a:n/a n/a
Sources
euvd EUVD-2020-21389

Description

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

References