Impact
A flaw in the Web-Page Crawling component of GreyDGL PentestGPT allows an attacker to manipulate the Traceback argument to inject code, leading to potential remote code execution. The vulnerability carries a low CVSS score of 2.3, indicating limited impact in isolation, but the injection capability could compromise confidentiality or integrity if exploited. The attack requires a high level of skill and is considered difficult to execute, though it has already been publicly disclosed.
Affected Systems
GreyDGL PentestGPT versions up to 1.0.0 are affected. The issue is documented for the component that performs web crawling and is referenced in GitHub repositories as well as vulnerability databases. No newer version information is provided in the current data set, so any deployment of version 1.0.0 or earlier is potentially vulnerable.
Risk and Exploitability
The low CVSS score reflects a modest threat profile, but the vulnerability is remotely exploitable and publicly available. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while the risk is currently low, continuous monitoring is prudent. The complexity and difficulty markers imply that a skilled attacker could discover and use the flaw, though widespread exploitation is unlikely without further advancement or known exploits.
OpenCVE Enrichment