PT-2026-71888 · Unknown · Openchoreo

CVE-2026-73667

·

Published

2026-08-13

·

Updated

2026-09-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenChoreo versions prior to 1.0.4 OpenChoreo versions prior to 1.1.4 OpenChoreo versions prior to 1.2.0-rc.2
Description OpenChoreo Workflow Plane templates located under samples/getting-started/workflow-templates/ interpolate developer-controlled workflow parameters into shell program text executed via sh -c rather than passing values through container.env. This allows the execution of arbitrary commands within workflow pods. Additionally, affected privileged Podman templates lack the hostUsers: false configuration.
Recommendations Update to version 1.0.4. Update to version 1.1.4. Update to version 1.2.0-rc.2.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73667
GHSA-2MW5-23GM-PCCQ
GO-2026-6357

Affected Products

Openchoreo