CVE-2026-76993
⚪ Do wiadomości
Wstrzyknięcie kodu w GreyDGL PentestGPT umożliwia zdalne wykonanie ataku.
CVSS
5.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned".
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-08-20 15:18:40 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-24 16:40:53 UTC |
Referencje
- https://github.com/GreyDGL/PentestGPT/ (cna@vuldb.com)
- https://github.com/GreyDGL/PentestGPT/issues/484 (cna@vuldb.com)
- https://github.com/ez-lbz/pentestgpt-vul-report (cna@vuldb.com)
- https://vuldb.com/cve/CVE-2026-76993 (cna@vuldb.com)
- https://vuldb.com/submit/880116 (cna@vuldb.com)
- https://vuldb.com/vuln/393617 (cna@vuldb.com)
- https://vuldb.com/vuln/393617/cti (cna@vuldb.com)