Free tools Windows power users keep installed
One-click scans. No signup required.
ShareLaTeX fixed the remote command-execution flaw CVE-2015-0934 in version 0.1.3. The vulnerability affected the Common LaTeX Service Interface (CLSI) before 0.1.3 and required an authenticated remote user; a filename containing backtick characters could trigger arbitrary code execution.
What was the ShareLaTeX remote command-execution vulnerability?
The National Vulnerability Database (NVD) describes CVE-2015-0934 as a flaw in CLSI before version 0.1.3, as used by ShareLaTeX before version 0.1.3. Its record says remote authenticated users could execute arbitrary code by supplying backtick characters in a filename. NVD’s CVE-2015-0934 record was published on March 3, 2015.
In practical terms, the issue was command injection through filename handling: backticks in the supplied filename could affect command execution in the CLSI path. SecurityWeek’s March 4, 2015 account says commands could run with the privileges of the ShareLaTeX process. The flaw therefore required authentication, but successful exploitation could still give an attacker the ability to run commands as that service account.
Which versions were affected, and what fixed the flaw?
CLSI versions earlier than 0.1.3 and ShareLaTeX versions earlier than 0.1.3 were affected. The reported fix was ShareLaTeX 0.1.3, which escaped shell special characters in the CLSI root path, according to SecurityWeek’s contemporaneous report.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
The NVD record lists a CVSS 2.0 score of 6.5. That is the score in NVD’s 2015 record, not a current assessment or a score from a later CVSS version.
Was the separate ShareLaTeX file-disclosure flaw fixed too?
No such conclusion follows from the CVE-2015-0934 fix. SecurityWeek discussed a second, distinct issue: CVE-2015-0933, a path-traversal flaw that could disclose files through LaTeX file inclusion. Its account said that issue remained unaddressed at the time and described a configuration workaround. The two vulnerabilities had different impacts: CVE-2015-0934 enabled command execution, while CVE-2015-0933 concerned information disclosure. SecurityWeek’s report covers both; NVD also maintains a separate CVE-2015-0933 record.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should operators of an old ShareLaTeX installation do?
Check the installed ShareLaTeX and CLSI versions against the affected range. The historical fix identified for CVE-2015-0934 is version 0.1.3. The cited historical records do not establish whether an old installation is still supported or provide a current upgrade procedure; consult maintained project documentation before planning an upgrade. Do not assume that addressing CVE-2015-0934 also resolves CVE-2015-0933.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

