CVE-2016-5713
CVE-2016-5713 is a critical-severity vulnerability in Puppet Puppet Agent with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 2% (79th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Puppet Puppet Agent
- Published:
- Last modified:
Description
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.
Frequently asked questions
- What is CVE-2016-5713?
- Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.
- How severe is CVE-2016-5713?
- CVE-2016-5713 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2016-5713 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (79th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2016-5713?
- CVE-2016-5713 affects Puppet Puppet Agent. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2016-5713?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2016-5713 published?
- CVE-2016-5713 was published on 2017-12-06 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:*
More vulnerabilities in Puppet Puppet Agent
- CVE-2021-27023 — Critical (CVSS 9.8): A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following…
- CVE-2016-2786 — Critical (CVSS 9.8): The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not…
- CVE-2016-2785 — Critical (CVSS 9.8): Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might…
- CVE-2016-5714 — High (CVSS 7.2): Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to…
- CVE-2021-27025 — Medium (CVSS 6.5): A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a…
- CVE-2020-7942 — Medium (CVSS 6.5): Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the…
All CVEs affecting Puppet Puppet Agent →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…