{"id":"CVE-2019-6986","aliases":["GHSA-hgq9-q8g2-3jmg"],"url":"https://o3.security/vulnerability/CVE-2019-6986","summary":"Command Injection in VIVO Vitro","details":"SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.","published":"2019-01-28T15:29:00.337Z","modified":"2026-07-08T23:46:46.203485Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.vivoweb:vitro-project","fixedVersion":"1.11.0"}],"fix":{"url":"https://github.com/vivo-project/Vitro/pull/111","label":"vivo-project/Vitro#111"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/172838/VIVO-SPARQL-Injection.html"},{"type":"FIX","url":"https://github.com/vivo-project/Vitro/pull/111"},{"type":"EVIDENCE","url":"https://github.com/kevinbackhouse/SecurityExploits/tree/0ec74459ac53685a7959ed58d580ef8abece3685/vivo-project"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6986"},{"type":"WEB","url":"https://github.com/vivo-project/Vitro/pull/111/commits/248ef19107a5ac6f86304fd8f3bc75f3787f8d49"},{"type":"PACKAGE","url":"https://github.com/vivo-project/Vitro"},{"type":"WEB","url":"https://jira.duraspace.org/browse/VIVO-1697"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T23:46:46.203485Z"}}