Description
A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: 1.8% Low
KEV: No
Impact: Remote OS Command Injection
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an OS command injection flaw in the ssh_run_command function of the HackingBuddyGPT project. By manipulating input to this function, an attacker can execute arbitrary shell commands, potentially gaining full system compromise. The flaw is rooted in improper handling of user-supplied data and maps to CWE-77 and CWE-78. Because the function can be reached over SSH, the attack can be launched from a remote network.

Affected Systems

The affected product is ipa‑lab's HackingBuddyGPT, version up to 0.5.0. Earlier releasesusers running any 0.5.0 or earlier build are potentially vulnerable.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate severity. EPSS score of 1% denotes a very low but non‑zero exploitation probability, and it is not listed in the CISA KEV catalog. The exposed SSH interface makes it an external attack vector, and the public exploit code available on the project's issue tracker increases the practical threat level. No vendor patch is currently available, so risk remains until mitigated.

Generated by OpenCVE AI on September 15, 2026 at 15:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply an official patch from ipa‑lab as soon as it becomes available.
  • If a patch cannot be applied immediately, implement input validation: sanitize or whitelist arguments passed to ssh_run_command before execution.
  • Use least‑privileged SSH accounts for the service and ensure that the account has only the permissions required for the intended function.
  • Restrict SSH access to trusted networks or host‑based authentication, and consider disabling the ssh_run_command feature until remediation is complete.

Generated by OpenCVE AI on September 15, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title ipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injection
First Time appeared Ipa-lab
Ipa-lab hackingbuddygpt
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:ipa-lab:hackingbuddygpt:*:*:*:*:*:*:*:*
Vendors & Products Ipa-lab
Ipa-lab hackingbuddygpt
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ipa-lab Hackingbuddygpt
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:21.148Z

Reserved: 2026-09-12T20:22:34.583Z

Link: CVE-2026-90621

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:18.307Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T04:16:35.673

Modified: 2026-09-15T14:17:26.197

Link: CVE-2026-90621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')