{"id":"CVE-2021-36711","aliases":["GHSA-fr75-x856-q6j8","PYSEC-2022-235"],"url":"https://o3.security/vulnerability/CVE-2021-36711","summary":"Octobot mishandles Tentacles upload","details":"WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.","published":"2022-07-16T17:15:08.440Z","modified":"2026-07-09T01:06:52.273406Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.15816,"percentile":0.96626,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"PyPI","name":"octobot","fixedVersion":"0.4.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/Drakkar-Software/OctoBot/blob/master/CHANGELOG.md"},{"type":"ADVISORY","url":"https://packetstormsecurity.com/files/167721/Sashimi-Evil-OctoBot-Tentacle.html"},{"type":"ADVISORY","url":"https://www.octobot.online/"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/167780/OctoBot-WebInterface-0.4.3-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://github.com/Drakkar-Software/OctoBot/issues/1966"},{"type":"EVIDENCE","url":"https://github.com/Nwqda/Sashimi-Evil-OctoBot-Tentacle"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36711"},{"type":"PACKAGE","url":"https://github.com/Drakkar-Software/OctoBot"},{"type":"WEB","url":"https://github.com/Drakkar-Software/OctoBot/blob/master/CHANGELOG.md#044---2022-06-01"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fr75-x856-q6j8"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/octobot/PYSEC-2022-235.yaml"},{"type":"WEB","url":"https://www.octobot.online"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:06:52.273406Z"}}