OliveTin has 6 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 3. The median CVSS is 5.4 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 4 prev 2
Worst active — by depth score
CVE-2026-67437High· 7.5OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)41CVE-2026-48708High· 7.5OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination41CVE-2026-67438Medium· 6.6OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check36CVE-2026-53541Medium· 4.3OliveTin gives access to predefined shell commands from a web interface24CVE-2026-67439Medium· 4.3OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output24
OliveTin vulnerabilities
CVEs affecting OliveTin, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-53541Medium· 4.3OliveTin gives access to predefined shell commands from a web interface
OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prio…
CVE-2026-67437High· 7.5OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
CVE-2026-67439Medium· 4.3OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
CVE-2026-67438Medium· 6.6OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
CVE-2026-48708High· 7.5OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
CVE-2026-48709Low· 3.7OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration
OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration