CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-23054

Critical · CVSS 9.8

Plone Docker Official Image — Dependency Confusion / Uncontrolled Search Path Element (npm package squatting leading to RCE)

CVSS
9.8
nvd
EPSS
1.68%
74th pct
KEV
No
Class
other
CWE-427, CWE-427

Description

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).

Search profile — drives PoC discovery

Symbols ++plone++static/componentsnpmplone-staticpackage.jsonplone docker image
Keywords CVE-2024-23054Plone Dockerdependency confusionnpm package squatting++plone++static/componentsPlone RCEplone 5.2.13CWE-427uncontrolled search pathplone npm missing package
Versions: 5.2.13 (5221)

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z