---
id: CVE-2026-90618
title: >-
  A flaw has been found in GH05TCREW PentestAgent up to
  cf882dabea3ed91cef016cdd115e5426315665a2
summary: >-
  A flaw has been found in GH05TCREW PentestAgent up to
  cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function
  LocalRuntime.execute_command of the file runtime/runtime.py of the component
  LocalRuntime. Executing a manipu…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
vendor: GH05TCREW
product: PentestAgent
affected:
  - PentestAgent cf882dabea3ed91cef016cdd115e5426315665a2
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90618'
references:
  - url: 'https://github.com/GH05TCREW/pentestagent/'
    label: cna@vuldb.com
  - url: 'https://github.com/GH05TCREW/pentestagent/issues/91'
    label: cna@vuldb.com
  - url: 'https://github.com/GH05TCREW/pentestagent/pull/100'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90618'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/914809'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403199'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403199/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T15:50:18.710598Z'
ingestedAt: '2026-09-14T15:23:07.467Z'
epss: 0.016
epssPercentile: 0.74305
---

## Overview

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
