Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
The product does not properly restrict reading from or writing to dynamically-identified variables.