PT-2026-29252 · Infcode+1 · Infcode+1
Secsys-Fdu
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2026-30309
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InfCode (affected versions not specified)
Description
The terminal auto-execution module in InfCode has a critical command filtering issue that makes its blacklist ineffective. The blacklist does not include native high-risk commands in Windows PowerShell, such as
powershell. The matching algorithm cannot recognize string concatenation, variable assignment, or double-quote interpolation in Shell syntax, preventing dynamic semantic parsing. Attackers can bypass interception using simple syntax obfuscation. A malicious file containing instructions for remote code injection can be created. When a user imports and views this file in the IDE, the Agent executes dangerous PowerShell commands outside the blacklist without user confirmation, potentially leading to arbitrary command execution or sensitive data leakage.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infcode
Windows Powershell