{"id":"CVE-2026-90617","title":"A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2","summary":"A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipula…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-77","CWE-78"],"vendor":"GH05TCREW","product":"PentestAgent","affected":["PentestAgent cf882dabea3ed91cef016cdd115e5426315665a2"],"published":"2026-09-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:19:37.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90617","references":[{"url":"https://github.com/GH05TCREW/pentestagent/","label":"cna@vuldb.com"},{"url":"https://github.com/GH05TCREW/pentestagent/issues/90","label":"cna@vuldb.com"},{"url":"https://github.com/GH05TCREW/pentestagent/pull/101","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90617","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/914808","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403198","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403198/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-15T17:23:46.994488Z"},"epss":0.016,"epssPercentile":0.74305,"ingestedAt":"2026-09-14T15:23:07.467Z","slug":"CVE-2026-90617","body":"## Overview\n\nA vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The pull request to fix this issue awaits acceptance.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":40.2,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":204344,"id":"CVE-2026-90617","ts":1789494100130,"field":"exploit_available","old":"false","new":"true"}]}