CVE-2021-47935EPSS p59.2%
CVE-2021-47935CVE-2021-47935
sentry / sentry
Description
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.93% probability of exploitation · percentile 59.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-20 |