Impact
A vulnerability exists in vxcontrol PentAGI up to version 2.1.0 within the backend pkg templates for the pentester tool. Manipulation of the pentester.tmpl file may cause a sandbox escape. The weakness involves improper access controls and privilege management (CWE‑264; CWE‑265). An attacker could gain control outside the intended sandbox, potentially compromising system integrity and confidentiality.
Affected Systems
The affected product is vxcontrol PentAGI version 2.1.0 or earlier. The vulnerability resides in the file backend/pkg/templates/prompts/pentester.tmpl of the Tool Management Protocol Handler component. No other products or versions are listed.
Risk and Exploitability
The CVSS score is 6.3, indicating a moderate severity. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog. The attack can be performed remotely, although the exploit requires a high level of complexity and is considered difficult. An exploit is publicly available, so administrators should treat this vulnerability as a moderate risk with a potentially long exposure window.
OpenCVE Enrichment