Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ruby: Node.js Toolkit: Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables. | |
| Weaknesses | CWE-96 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-15T13:28:53.581Z
Reserved: 2026-07-30T15:00:00.609Z
Link: CVE-2026-68489
Updated: 2026-09-15T13:28:50.369Z
Status : Received
Published: 2026-09-14T21:17:25.567
Modified: 2026-09-15T14:17:07.550
Link: CVE-2026-68489
OpenCVE Enrichment
Updated: 2026-09-16T08:30:17Z