{"id":"CVE-2021-23420","details":"This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.","aliases":["GHSA-4574-qv3w-fcmg"],"modified":"2026-07-09T14:06:14.488501Z","published":"2021-08-11T13:15:16.057Z","references":[{"type":"WEB","url":"https://github.com/Codeception/Codeception/blob/4.1/ext/RunProcess.php%23L52"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PHP-CODECEPTIONCODECEPTION-1324585"},{"type":"FIX","url":"https://github.com/Codeception/Codeception/pull/6241"},{"type":"EVIDENCE","url":"https://github.com/JinYiTong/poc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/codeception/codeception","events":[{"introduced":"0"},{"fixed":"5ce5d0e2064b5590c19709c75fc4c621b1236b32"},{"introduced":"03d7e33c155bf9da306f0209d520fb8423f6dd67"},{"fixed":"9777ec3690ceedc4bce2ed13af7af4ca4ee3088f"}],"database_specific":{"cpe":"cpe:2.3:a:codeception:codeception:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.1.3"},{"introduced":"4.0.0"},{"fixed":"4.1.22"}],"source":"CPE_RANGE"}}],"versions":["3.1.2","4.1.21","4.1.20","4.1.19","4.1.18","4.1.17","4.1.16","4.1.15","4.1.14","4.1.13","4.1.12","4.1.11","4.1.9","4.1.8","4.1.7","4.0.3","4.1.6","4.1.5","4.1.4","4.1.3","4.1.2","4.1.1","4.1.0","4.0.2","4.0.1","4.0.0","3.1.1","3.1.0","3.0.3","3.0.2","3.0.1","3.0.0","2.5.3","2.5.2","2.5.1","2.5.0","2.4.5","2.4.4","2.4.3","2.4.2","2.4.1","2.4.0","2.3.8","2.3.7","2.3.6","2.3.5","2.3.0","2.3.4","2.3.3","2.3.2","2.3.1","2.2.0-RC2","2.0.0-RC","2.2.0-RC","2.2.0-beta","2.1.5","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.1.0-rc1","2.1.0-beta","2.0.0-RC2","2.0.0-beta","2.0.0-alpha","1.8.0","1.6.4","1.6.3.1","1.6.3","1.6.2","1.6.1.1","1.6.1","1.6.0.4","1.6.0.3","1.6.0.1","1.6.0","1.5.7","1.5.6","1.5.5","1.5.4","1.5.3","1.5.2","1.5.1","1.5.0","1.1.5","1.1.4","1.1.3","1.1.2","1.1.0","1.0.14","1.0.13","1.0.12","1.0.11","1.0.10","1.0.9","v1.0.1","1.01a","1.01","1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23420.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}