{"api_version":"1","generated_at":"2026-07-23T15:32:48+00:00","cve":"CVE-2020-29007","urls":{"html":"https://cve.report/CVE-2020-29007","api":"https://cve.report/api/cve/CVE-2020-29007.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-29007","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-29007"},"summary":{"title":"CVE-2020-29007","description":"The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-04-15 22:15:00","updated_at":"2023-04-26 16:13:00"},"problem_types":["CWE-94"],"metrics":[],"references":[{"url":"https://github.com/seqred-s-a/cve-2020-29007","name":"https://github.com/seqred-s-a/cve-2020-29007","refsource":"MISC","tags":[],"title":"GitHub - seqred-s-a/cve-2020-29007: Remote code execution in Mediawiki Score","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.mediawiki.org/wiki/Extension:Score","name":"https://www.mediawiki.org/wiki/Extension:Score","refsource":"MISC","tags":[],"title":"Extension:Score - MediaWiki","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/","name":"https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/","refsource":"MISC","tags":[],"title":"CVE-2020-29007 – remote code execution in Mediawiki Score | SEQRED","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory","name":"https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory","refsource":"MISC","tags":[],"title":"Extension:Score/2021 security advisory - MediaWiki","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://phabricator.wikimedia.org/T257062","name":"https://phabricator.wikimedia.org/T257062","refsource":"MISC","tags":[],"title":"Login","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-29007","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-29007","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"29007","vulnerable":"1","versionEndIncluding":"0.3.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mediawiki","cpe5":"score","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"mediawiki","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-29007","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/seqred-s-a/cve-2020-29007","refsource":"MISC","name":"https://github.com/seqred-s-a/cve-2020-29007"},{"url":"https://www.mediawiki.org/wiki/Extension:Score","refsource":"MISC","name":"https://www.mediawiki.org/wiki/Extension:Score"},{"refsource":"MISC","name":"https://phabricator.wikimedia.org/T257062","url":"https://phabricator.wikimedia.org/T257062"},{"refsource":"MISC","name":"https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/","url":"https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/"},{"refsource":"MISC","name":"https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory","url":"https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory"}]}},"nvd":{"publishedDate":"2023-04-15 22:15:00","lastModifiedDate":"2023-04-26 16:13:00","problem_types":["CWE-94"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mediawiki:score:*:*:*:*:*:mediawiki:*:*","versionEndIncluding":"0.3.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"29007","Ordinal":"192070","Title":"CVE-2020-29007","CVE":"CVE-2020-29007","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"29007","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}