Vulnerability CVE-2024-1651


Published: 2024-02-20

Description:
Torrentpier version 2.4.1 allows executing arbitrary commands on the server.

This is possible because the application is vulnerable to insecure deserialization.




Type:

CWE-502

(Deserialization of Untrusted Data)

 References:
https://github.com/torrentpier/torrentpier
https://fluidattacks.com/advisories/xavi/

Copyright 2026, cxsecurity.com

 

Back to Top