CVE-2026-90618: GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection
A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.executecommand of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
Does exploitation appear to require prior access or user interaction?
The supplied CVSS vector indicates no privileges and no user interaction are required. The issue is described as remotely exploitable.
Is exploit code available?
Yes. The exploit has been published and may be used.
Which releases should be treated as potentially affected?
GH05TCREW PentestAgent versions up to commit cf882dabea3ed91cef016cdd115e5426315665a2 are identified as affected.
Is an accepted fix currently available?
The referenced pull request to fix the issue is awaiting acceptance. The provided data does not identify an accepted remediation.