PT-2026-43702 · Undefined · Undefined
Anmol Vats
·
Published
2026-05-27
·
Updated
2026-05-27
·
CVE-2026-36044
CVSS v3.1
8.8
High
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:R |
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child process.exec(). Because exec() spawns a shell, shell metacharacters in those values are interpreted by the host shell, resulting in arbitrary OS command execution with the privileges of the running process.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined