PT-2026-29252 · Infcode+1 · Infcode+1

Secsys-Fdu

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-30309

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InfCode (affected versions not specified)
Description The terminal auto-execution module in InfCode has a critical command filtering issue that makes its blacklist ineffective. The blacklist does not include native high-risk commands in Windows PowerShell, such as powershell. The matching algorithm cannot recognize string concatenation, variable assignment, or double-quote interpolation in Shell syntax, preventing dynamic semantic parsing. Attackers can bypass interception using simple syntax obfuscation. A malicious file containing instructions for remote code injection can be created. When a user imports and views this file in the IDE, the Agent executes dangerous PowerShell commands outside the blacklist without user confirmation, potentially leading to arbitrary command execution or sensitive data leakage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30309

Affected Products

Infcode
Windows Powershell