NSA
NSA Emissary: vulnerabilidades y CVE
NSA Emissary tiene 14 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses5
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-35582 | Alta (8.8) | 1.1% | — | 18 abr 2026 | Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /bin/sh -c shell… |
| CVE-2026-35583 | Media (5.3) | 0.41% | — | 7 abr 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration/{name}) validated configuration names using a blacklist approach that checked for \, /, .., and… |
| CVE-2026-35581 | Alta (7.2) | 0.90% | — | 7 abr 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell commands by concatenating configuration-derived values — including the PLACE_NAME parameter — with… |
| CVE-2026-35580 | Crítica (9.1) | 0.69% | — | 7 abr 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell… |
| CVE-2026-35571 | Media (4.8) | 0.26% | — | 7 abr 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, Mustache navigation templates interpolated configuration-controlled link values directly into href attributes without URL scheme validation. An… |
| CVE-2025-27508 | Alta (7.5) | 0.21% | — | 5 mar 2025 | Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum generation, but it includes or defaults to algorithms that are no longer recommended for secure… |
| CVE-2021-32639 | Crítica (9.9) | 1.4% | — | 2 jul 2021 | Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the `RegisterPeerAction` endpoint and the `AddChildDirectoryAction`… |
| CVE-2021-32647 | Crítica (9.1) | 2.9% | — | 1 jun 2021 | Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE). The… |
| CVE-2021-32634 | Alta (7.2) | 1.3% | — | 21 may 2021 | Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the… |
| CVE-2021-32093 | Media (6.5) | 1.0% | — | 7 may 2021 | The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the ConfigName parameter. |
| CVE-2021-32092 | Media (6.1) | 0.95% | — | 7 may 2021 | A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the uuid parameter. |
| CVE-2021-32096 | Alta (8.8) | 0.59% | — | 7 may 2021 | The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter. |
| CVE-2021-32095 | Alta (8.1) | 0.89% | — | 7 may 2021 | U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files. |
| CVE-2021-32094 | Alta (8.8) | 1.2% | — | 7 may 2021 | U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.