PT-2026-43702 · Unknown · @Pensar/Apex

·

CVE-2026-36044

·

Published

2026-05-27

·

Updated

2026-05-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @pensar/apex versions prior to 0.0.59
Description OS command injection is possible via the smart enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child process.exec(). Since exec() spawns a shell, shell metacharacters in these values are interpreted by the host shell, allowing arbitrary OS command execution with the privileges of the running process.
Recommendations Update @pensar/apex to version 0.0.59 or later. As a temporary workaround, restrict access to the createSmartEnumerateTool() function to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36044

Affected Products

@Pensar/Apex