PT-2026-65910 · Olivetin · Olivetin

CVE-2026-67438

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OliveTin versions 3000.2.0 through 3000.16.0
Description OS command injection is possible because the checkShellArgumentSafety() function in service/internal/executor/arguments.go fails to treat regex: custom argument types as unsafe for Shell mode actions. This allows values that pass the typeSafetyCheckRegex to be interpolated by wrapCommandInShell() into an sh -c command string.
Recommendations Update to version 3000.17.0.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67438
GHSA-XC5W-4V5W-7X65

Affected Products

Olivetin