CVE-2026-51881: Code Injection
Published Oct 1, 2026
·Updated
deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell commands in the service environment.
Affected Software
0 affected components
Event History
Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs remote access to the live tutorbot WebSocket interface and must be able to send input that induces the tool layer to invoke ExecTool.execute.
2
What is the impact of successful exploitation?
A successful attacker can cause reviewer-chosen shell commands to run in the service environment, resulting in remote code execution with the privileges available to that service.
3
Which deployments are known to be affected?
The provided information identifies deeptutor version 1.4.0 as affected. It does not state whether other versions or default configurations are affected.