Exploit Title: Algorithmia MSOL - Remote Code Execution Date: 9/28/2021 Vendor Homepage: https://algorithmia.com/ Software Link: https://algorithmia.com/product Version: Affects all versions of the product up to the date of this submission Tested on: The issue affects all versions of the product up to the date of this submission Exploit Authors: Josh Sheppard & Pathfynder Inc Exploit Contact: ghost a t undervurse dot_com & josh a t pathfynder dot_io Exploit Technique: Remote CVE ID: CVE-2021-42951 1. Description A remote code execution vulnerability has been discovered in Algorithmia MSOL product. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new, specially crafted Algorithm and subsequently launch remote code execution with their desired result. This vulnerability effects all of their current Algorithm source languages including: - python 2.x, 3.x - c# code 2.x - scala 2.x - rust The issue affects all versions of the product up to the date of this submission. 2. Disclosure Timeline 9/28/21 - Discovery and Exploitation 9/28/21 - Vendor Notified 2/16/22 - CVE Assigned 2/17/22 - Public Disclosure 3. Mitigation Hotfix applied to vendors SAAS solution, no action is necessary at this time however, vendor may recommend users upgrade current Algorithms.