Description
A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack remotely. The attack-s complexity is rated as high. The exploitation appears to be difficult. The project was informed of the problem early through a pull request but has not reacted yet.
CVSS 5EPSS 0.219%Risk 0.51
View source- Published
- 2026-05-26 19:16:34
- Affected versions
- <=4.3.1.1
- Type
- Core software
- Last modified
- 2026-07-23 11:10:00
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L