Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance. | |
| Title | GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection | |
| First Time appeared |
Gh05tcrew
Gh05tcrew pentestagent |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:gh05tcrew:pentestagent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gh05tcrew
Gh05tcrew pentestagent |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T02:30:11.139Z
Reserved: 2026-09-12T20:02:08.658Z
Link: CVE-2026-90618
No data.
Status : Received
Published: 2026-09-14T03:16:37.263
Modified: 2026-09-14T03:16:37.263
Link: CVE-2026-90618
No data.
OpenCVE Enrichment
No data.