Impact
An attacker can supply crafted input to the run_task endpoint of the MCP HTTP Server in GH05TCREW PentestAgent, causing the input to be executed as an operating system command on the host machine; this results in remote code execution with the privileges of the agent process and is classified as CWE-77 and CWE-78.
Affected Systems
The vulnerability affects all builds of GH05TCREW PentestAgent that include the MCP HTTP Server component, specifically any version released before the pull request that applies the fix is merged, up to commit cf882dabea3ed91cef016cdd115e5426315665a2; versioning is not specified due to the product’s rolling release model.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, the EPSS score of 2% shows a low but non‑zero likelihood of automated exploitation, and the vulnerability is not listed in CISA’s KEV catalog; because remote execution is possible over the network, the risk is significant for exposed instances of the MCP HTTP Server.
OpenCVE Enrichment