ICEcoder 8.1 Remote Code Execution Vulnerability: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- icecoder (npm)
- Affected versions
- >= 8.0, <= 8.0 or >= 8.0beta, <= 8.0beta or >= 7.0beta, <= 7.0beta or >= 7.0, <= 7.0 or >= v6.0, <= v6.0 or >= v6.0beta, <= v6.0beta or >= v5.7, <= v5.7 or >= v5.6, <= v5.6 or >= v5.5, <= v5.5 or >= v5.4, <= v5.4 or >= v5.3, <= v5.3 or >= v5.2, <= v5.2 or >= v5.1, <= v5.1 or >= v5.0, <= v5.0 or >= v5.0beta, <= v5.0beta or >= v4.5, <= v4.5 or >= v4.4, <= v4.4 or >= v4.3, <= v4.3 or >= v4.2, <= v4.2 or >= v4.1, <= v4.1 or >= v4.0, <= v4.0 or >= v4.0beta, <= v4.0beta or >= v3.5, <= v3.5 or >= v3.4, <= v3.4 or >= v3.3, <= v3.3 or >= v3.2, <= v3.2 or >= v3.1, <= v3.1 or >= v3.0, <= v3.0 or >= v3.0beta, <= v3.0beta or >= v2.5, <= v2.5 or >= v2.4, <= v2.4 or >= v2.3, <= v2.3 or >= v2.2, <= v2.2 or >= v2.1, <= v2.1 or >= v2.0, <= v2.0 or >= v2.0beta, <= v2.0beta or >= v1.6, <= v1.6 or >= v1.5, <= v1.5 or >= v1.4, <= v1.4 or >= v1.3, <= v1.3 or >= v1.2, <= v1.2 or >= v1.1, <= v1.1 or >= v1.0.0, <= v1.0.0 or >= v0.9.1, <= v0.9.1 or >= v0.9.0, <= v0.9.0 or >= v0.8.6, <= v0.8.6 or >= v0.8.5, <= v0.8.5 or >= v0.8.4, <= v0.8.4 or >= v0.8.3, <= v0.8.3 or >= v0.8.2, <= v0.8.2 or >= v0.8.1, <= v0.8.1 or >= v0.8.0, <= v0.8.0 or >= v0.7.9, <= v0.7.9 or >= v0.7.8, <= v0.7.8 or >= v0.7.7, <= v0.7.7 or >= v0.7.6, <= v0.7.6 or >= v0.7.5, <= v0.7.5 or >= v0.7.4, <= v0.7.4 or >= v0.7.3, <= v0.7.3 or >= v0.7.2, <= v0.7.2 or >= v0.7.1, <= v0.7.1 or >= v0.7.0, <= v0.7.0 or >= v0.6.9, <= v0.6.9 or >= v0.6.8, <= v0.6.8 or >= v0.6.7, <= v0.6.7 or >= v0.6.6, <= v0.6.6 or >= v0.6.5, <= v0.6.5 or >= v0.6.4, <= v0.6.4 or >= v0.6.3, <= v0.6.3 or >= v0.6.2, <= v0.6.2 or >= v0.6.1, <= v0.6.1 or >= v0.6.0, <= v0.6.0 or >= v0.5.9, <= v0.5.9
- Patched version
- Not yet available
ICEcoder 8.1 is under investigation for an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary OS commands. Users of affected versions should assess their exposure immediately.
What happened
ICEcoder 8.1 reportedly contains a vulnerability that permits unauthenticated remote code execution. Attackers can exploit this by sending a specially crafted HTTP POST request to the terminal endpoint. This allows them to bypass authentication and CSRF validation, and execute arbitrary commands as the web-server user.
The vulnerability affects all versions of ICEcoder from 0.5.9 and above. The specific versions impacted range from v0.5.9 to v8.1 inclusive. There is currently no official fix published, and users are advised to monitor updates from the primary sources.
What to do about it
- Monitor the primary sources for updates on a patched version of ICEcoder.
- If a patched version becomes available, upgrade to it immediately.
- In the absence of a patch, consider removing or isolating the affected ICEcoder instances from your environment.
- Review your network and server configurations to limit the potential impact of remote code execution.
- Stay informed by consulting the primary sources listed below for the latest information.
How 0Day would have caught this
icecoder is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using any version of ICEcoder from v0.5.9 to v8.1 inclusive.
What should I do right now?
Monitor the primary sources for updates on a patched version. If a patch becomes available, upgrade immediately. In the absence of a patch, consider removing or isolating the affected ICEcoder instances.
Is there a patched version available?
No official fix has been published yet. Continue to monitor the primary sources for updates.
How can I limit the impact of this vulnerability?
Review your network and server configurations to limit the potential impact of remote code execution.