Impact
The flaw resides in the LocalRuntime.execute_command function of PentestAgent, where user-controlled input is concatenated and passed directly to the operating system shell. This allows an attacker who can invoke the function remotely to inject arbitrary shell commands, resulting in the execution of code with the privileges of the PentestAgent process. The weakness is consistent with CWE-77 and CWE-78, both representing command injection vulnerabilities.
Affected Systems
All installations of GH05TCREW PentestAgent that incorporate the code prior to the commit cf882dabea3ed91cef016cdd115e5426315665a2 are affected. The vulnerability exists in the runtime/runtime.py component; any release that has not integrated the pending fix is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as medium risk. An EPSS score of 2% indicates a low but non‑zero likelihood that this vulnerability is being exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack may be carried out from remote through an exposed request to the LocalRuntime.execute_command endpoint; successful exploitation would grant an attacker the ability to run arbitrary commands on the host machine.
OpenCVE Enrichment