Description
A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: 2.1% Low
KEV: No
Impact: Command Injection
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the LocalRuntime.execute_command function of PentestAgent, where user-controlled input is concatenated and passed directly to the operating system shell. This allows an attacker who can invoke the function remotely to inject arbitrary shell commands, resulting in the execution of code with the privileges of the PentestAgent process. The weakness is consistent with CWE-77 and CWE-78, both representing command injection vulnerabilities.

Affected Systems

All installations of GH05TCREW PentestAgent that incorporate the code prior to the commit cf882dabea3ed91cef016cdd115e5426315665a2 are affected. The vulnerability exists in the runtime/runtime.py component; any release that has not integrated the pending fix is vulnerable.

Risk and Exploitability

The CVSS score of 6.9 classifies the flaw as medium risk. An EPSS score of 2% indicates a low but non‑zero likelihood that this vulnerability is being exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack may be carried out from remote through an exposed request to the LocalRuntime.execute_command endpoint; successful exploitation would grant an attacker the ability to run arbitrary commands on the host machine.

Generated by OpenCVE AI on September 15, 2026 at 15:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the pending patch when the pull request is merged.
  • Disable or remove the LocalRuntime.execute_command feature until a fix is available, or restrict its exposure to trusted users only.
  • Add input validation or sanitization around command arguments before they reach os.system or similar calls.
  • Limit remote access to the component via firewall rules, VPN, or other network controls to reduce the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Title GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection
First Time appeared Gh05tcrew
Gh05tcrew pentestagent
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:gh05tcrew:pentestagent:*:*:*:*:*:*:*:*
Vendors & Products Gh05tcrew
Gh05tcrew pentestagent
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gh05tcrew Pentestagent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:51:40.747Z

Reserved: 2026-09-12T20:02:08.658Z

Link: CVE-2026-90618

cve-icon Vulnrichment

Updated: 2026-09-14T15:51:03.815Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T03:16:37.263

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:48Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')