Junglewise Threat Intelligence

CVE-2026-39052: Oinone Pamirs remote code execution in ScriptRunner

CVE-2026-39052 · Severity: medium · CVSS 6.5 · Published 2026-05-15

Technologies: Oinone Pamirs, Oinone Pamirs Framework. Vendors: Oinone.

Executive brief

Oinone Pamirs, a low-code framework used for building enterprise applications, contains a vulnerability that allows for arbitrary code execution. An attacker can exploit this by submitting malicious scripts to certain application features, potentially gaining full control over the server, accessing sensitive data, or disrupting business operations.

Technical details

A remote code execution (RCE) vulnerability exists in Oinone Pamirs 7.0.0 within the 'pamirs-framework-faas' module. The 'ScriptRunner.run' method evaluates attacker-controlled script expressions (such as Groovy or Java) using the underlying script engine without implementing a sandbox, allowlist, or capability controls. An attacker can exploit this by providing malicious input to any application endpoint, workflow, or plugin that utilizes this method. Successful exploitation allows for arbitrary code execution within the application process, potentially leading to unauthorized file access, network pivoting, or full operating system command execution.

Affected products

  • Oinone Pamirs (Pamirs Framework) 7.0.0

Timeline

  • 2026-05-15: disclosed: Vulnerability details published via GitHub Gist and NVD.
  • 2026-05-15: advisory

References

Related threats