PT-2026-29252 · Infcode+1 · Infcode+1
Secsys-Fdu
·
Publicado
2026-03-31
·
Atualizado
2026-03-31
·
CVE-2026-30309
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InfCode (affected versions not specified)
Description
The terminal auto-execution module in InfCode has a critical command filtering issue that makes its blacklist ineffective. The blacklist does not include native high-risk commands in Windows PowerShell, such as
powershell. The matching algorithm cannot recognize string concatenation, variable assignment, or double-quote interpolation in Shell syntax, preventing dynamic semantic parsing. Attackers can bypass interception using simple syntax obfuscation. A malicious file containing instructions for remote code injection can be created. When a user imports and views this file in the IDE, the Agent executes dangerous PowerShell commands outside the blacklist without user confirmation, potentially leading to arbitrary command execution or sensitive data leakage.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Infcode
Windows Powershell