Junglewise Threat Intelligence

CVE-2026-76993: GreyDGL PentestGPT argument injection in web-page crawling

CVE-2026-76993 · Severity: medium · CVSS 5 · Published 2026-08-20

Executive brief

GreyDGL PentestGPT is an automated penetration testing tool powered by large language models. A vulnerability in the web-page crawling component allows remote attackers to inject malicious input through the Traceback argument, potentially leading to code execution or information disclosure. The vulnerability can be exploited remotely but requires moderate technical sophistication.

Technical details

The vulnerability is an argument injection flaw in the web-page crawling component of PentestGPT up to version 1.0.0. The Traceback argument is not properly validated or sanitized, allowing an attacker to inject arbitrary input. The attack is network-reachable and can be executed remotely, though exploitation is noted as difficult and requires high attack complexity. An attacker can manipulate the Traceback parameter to inject code or commands, potentially achieving remote code execution or other malicious outcomes. The vendor has closed the reported issue as "not planned," indicating no patch is anticipated.

Affected products

  • GreyDGL PentestGPT up to 1.0.0

Timeline

  • 2026-07-04: disclosed: GitHub issue #484 opened
  • 2026-08-20: advisory: CVE-2026-76993 published

References

Related threats