PT-2026-65910 · Olivetin · Olivetin
CVE-2026-67438
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OliveTin versions 3000.2.0 through 3000.16.0
Description
OS command injection is possible because the
checkShellArgumentSafety() function in service/internal/executor/arguments.go fails to treat regex: custom argument types as unsafe for Shell mode actions. This allows values that pass the typeSafetyCheckRegex to be interpolated by wrapCommandInShell() into an sh -c command string.Recommendations
Update to version 3000.17.0.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Olivetin