CyberSec.Space Logo
Back to CVE Browser

CVE-2026-67438

MEDIUM
6.6
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-29
Last Modified2026-07-29
Data SourcesNVD

Vulnerability Description

OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument types as unsafe for Shell mode actions, allowing values that pass typeSafetyCheckRegex to be interpolated by wrapCommandInShell into an sh -c command string and enabling OS command injection. This issue is fixed in version 3000.17.0.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities

CVE-2026-67438 Detail & Impact Analysis | CVSS 6.6 (MEDIUM) | Cyber-Sec.Space | Cyber-Sec.Space