AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-5713

CRITICAL · CVSS 9.8 EPSS 2.02%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-12-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-5713
Severity
CRITICAL
CVSS
9.8
EPSS
2.02%

Original NVD Description

Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)