consoleme
A central control plane for AWS permissions and access
Activity
- Latest release
- 2y ago
- Total releases
- 59
- Cadence
- ~daily
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Jul 02, 2020
| Version | Released | |
|---|---|---|
1.4.0
minor
| ||
1.3.2.dev1
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.1.dev3
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev12
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev11
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev10
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev9
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev8
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev7
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev6
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev5
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev4
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev3
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev2
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.3.dev1
pre
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.2
patch
1 CVE
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.2.dev4
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.2.2.dev3
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.2.1.dev1
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.10.dev6
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.10.dev4
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.10.dev5
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.10.dev3
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.10.dev2
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.10.dev1
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.9
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.9.dev1
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.8
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.8.dev4
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.8.dev3
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.8.dev2
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.8.dev1
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.7
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.6
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.6.dev2
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.6.dev1
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.5
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.5.dev3
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.5.dev2
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.5.dev1
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.4
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.3
patch
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.3.dev8
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.3.dev7
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.3.dev6
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev | ||
1.1.3.dev5
pre
2 CVEs
CVE-2024-5023
PYSEC-2026-318
GHSA-3783-62vc-jr7x
Jun 29, 2026
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
ID: NFLX-2024-002ImpactAuthenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation. Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected. To determine if your ConsoleMe deployment uses templated resources, check the configuration value for DescriptionThe self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process. PatchesThis issue has been patched in version v1.4.0 via https://github.com/Netflix/consoleme/pull/9380.
If you are unable to upgrade to the latest version, users can selectively apply the code changes in the above PR. Alternatively, removing the configuration item CreditAffected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 46 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2
1.2.2.dev3
1.2.2.dev4
1.2.3.dev1
1.2.3.dev10
1.2.3.dev11
1.2.3.dev12
1.2.3.dev2
1.2.3.dev3
1.2.3.dev4
1.2.3.dev5
1.2.3.dev6
1.2.3.dev7
1.2.3.dev8
1.2.3.dev9
1.3.0
1.3.1
1.3.1.dev3
1.3.2.dev1
Fixed in
1.4.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-27177
GHSA-74w3-2r77-fw5h
PYSEC-2022-189
Apr 03, 2022
Use of Externally-Controlled Format String in consoleme
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 Affected versions
0.0.0
1.0.6.dev10
1.1.1
1.1.10.dev1
1.1.10.dev2
1.1.10.dev3
1.1.10.dev4
1.1.10.dev5
1.1.10.dev6
1.1.2
1.1.2.dev1
1.1.3
+ 29 more Show less
1.1.3.dev1
1.1.3.dev2
1.1.3.dev3
1.1.3.dev4
1.1.3.dev5
1.1.3.dev6
1.1.3.dev7
1.1.3.dev8
1.1.4
1.1.5
1.1.5.dev1
1.1.5.dev2
1.1.5.dev3
1.1.6
1.1.6.dev1
1.1.6.dev2
1.1.7
1.1.8
1.1.8.dev1
1.1.8.dev2
1.1.8.dev3
1.1.8.dev4
1.1.9
1.1.9.dev1
1.2.0
1.2.1
1.2.1.dev1
1.2.2.dev3
1.2.2.dev4
Fixed in
1.2.2
References
Updated Feb 18, 2025 · Source: OSV.dev |