PT-2026-91031 · Gh05Tcrew · Pentestagent

·

CVE-2026-90617

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GH05TCREW PentestAgent versions up to cf882dabea3ed91cef016cdd115e5426315665a2
Description An OS command injection flaw exists in the MCP HTTP Server component within the run task() function of the interface/main.py file. This issue allows a remote attacker to execute arbitrary operating system commands through manipulation of the input.
Recommendations As a temporary workaround, restrict access to the run task() function in the interface/main.py file until the pending pull request is accepted and merged.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90617

Affected Products

Pentestagent