CVE-2026-68489

Summary

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.

Affected Software

VendorProductVersion RangeStatus
WebProsPlesk extension “Ruby”0 < 1.6.6affected
WebProsPlesk extension “Node.js Toolkit”0 < 2.5.0affected

Weaknesses

  • CWE-96: CWE-96 Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

References