PT-2026-29102 · Syntx · Syntx
Secsys-Fdu
·
Published
2026-03-30
·
Updated
2026-04-08
·
CVE-2026-30305
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Syntx (affected versions not specified)
Description
The command auto-approval module contains a critical OS command injection issue that bypasses its whitelist security mechanism. The system uses weak regular expressions to parse command structures and fails to account for Shell command substitution syntax, specifically $(...) and backticks (...). An attacker can craft a command, such as
git log --grep="$(malicious command)", which is incorrectly identified as a safe git operation and automatically approved. The underlying Shell then prioritizes the execution of the injected malicious code, leading to Remote Code Execution without user interaction. The git log command utilizes the API endpoint /git/log and the vulnerable parameter grep which accepts the malicious command variable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syntx