Junglewise Threat Intelligence

CVE-2026-90618: GH05TCREW PentestAgent OS command injection in LocalRuntime

CVE-2026-90618 · Severity: high · CVSS 7.3 · Published 2026-09-14

Executive brief

PentestAgent is an AI-powered penetration testing framework that automates security assessments by executing commands on a target system. The LocalRuntime component executes shell commands generated by an AI agent without validation or sandboxing. An attacker can inject malicious commands through target system responses (e.g., HTTP body content, DNS records), causing the framework to execute arbitrary code on the operator's machine with full user privileges.

Technical details

The vulnerability is an OS command injection flaw in the LocalRuntime.execute_command function (runtime/runtime.py), which uses asyncio.create_subprocess_shell to execute LLM-generated commands without validation. The root cause is the absence of command filtering, sandboxing, or filesystem isolation. The attack vector is network-based: an attacker-controlled target system injects prompt-injection payloads into its responses; these responses are fed into the LLM context, which generates malicious terminal commands that are then executed directly on the host. No authentication is required—any reachable target can exploit this. An attacker achieves arbitrary code execution in the operator's context, enabling credential theft, persistence, and lateral movement. A fix is pending in a pull request awaiting acceptance.

Affected products

  • GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

Timeline

  • 2026-09-14: disclosed
  • 2026-08-04: exploited: Proof of concept and attack chain published in GitHub issue #91

References

Related threats