Technology · Go
github.com/OliveTin/OliveTin (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in github.com/OliveTin/OliveTin (Go): 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-53541, was published on 21 August 2026.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 0
- Exploited in the wild
- 0
About github.com/OliveTin/OliveTin (Go)
A web interface for executing shell commands on a server.
Latest github.com/OliveTin/OliveTin (Go) vulnerabilities
- CVE-2026-53541: OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in…mediumCVSS 4.3EPSS 0.4%
- CVE-2026-67439: OliveTin incorrect authorization in synchronous execution endpointsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-67438: OliveTin OS command injection in regex argument validationmediumCVSS 6.6EPSS 1.6%
- CVE-2026-67437: OliveTin memory exhaustion via unbounded OAuth2 state map growthhighCVSS 7.5EPSS 0.6%
- CVE-2026-48709: OliveTin missing authorization in ValidateArgumentType APIlowCVSS 3.7EPSS 0.4%
- CVE-2026-48708: OliveTin race condition in template engine causing command contaminationhighCVSS 7.5EPSS 0.5%
- GO-2026-4687 - OliveTin's email argument makes compliance harder, enables log injection in github.com/OliveTin/OliveTininfo
- CVE-2026-31817: GO-2026-4670 - OliveTin's unsafe parsing of UniqueTrackingId can be used to write files in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 0.9%
- CVE-2026-32102: GO-2026-4683 - OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream in github.com/OliveTin/OliveTinmediumCVSS 4EPSS 0.5%
- OliveTin's email argument makes compliance harder, enables log injectionmediumCVSS 4
- GO-2026-4621 - OliveTin has crash on NPE by calling APIs with invalid bindings or log references in github.com/OliveTin/OliveTininfo
- CVE-2026-30233: GO-2026-4629 - OliveTin doesn't check view permission when returning dashboards in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 0.5%
- CVE-2026-30223: GO-2026-4622 - OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 0.3%
- CVE-2026-30224: GO-2026-4623 - OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 0.4%
- CVE-2026-30225: GO-2026-4625 - OliveTin's RestartAction always runs actions as guest in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 0.6%
- CVE-2026-28790: GO-2026-4587 - OliveTin has Unauthenticated Action Termination via KillAction When Guests Must Login in…lowCVSS 3.1EPSS 0.8%
- CVE-2026-28342: GO-2026-4584 - OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint in…lowCVSS 3.1EPSS 0.8%
- CVE-2026-28789: GO-2026-4586 - OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handling in…lowCVSS 3.1EPSS 0.5%
- OliveTin has crash on NPE by calling APIs with invalid bindings or log referenceslowCVSS 3.1
- CVE-2026-27626: GO-2026-4547 - OliveTin: OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell…lowCVSS 3.1EPSS 0.7%
- CVE-2025-50946: GO-2025-3886 - OliveTin OS Command Injection vulnerability in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 1.3%
Most severe github.com/OliveTin/OliveTin (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-67437: OliveTin memory exhaustion via unbounded OAuth2 state map growthhighCVSS 7.5EPSS 0.6%
- CVE-2026-48708: OliveTin race condition in template engine causing command contaminationhighCVSS 7.5EPSS 0.5%
- CVE-2026-67438: OliveTin OS command injection in regex argument validationmediumCVSS 6.6EPSS 1.6%
- CVE-2026-67439: OliveTin incorrect authorization in synchronous execution endpointsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-53541: OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in…mediumCVSS 4.3EPSS 0.4%
- CVE-2026-32102: GO-2026-4683 - OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream in github.com/OliveTin/OliveTinmediumCVSS 4EPSS 0.5%
- OliveTin's email argument makes compliance harder, enables log injectionmediumCVSS 4
- CVE-2026-48709: OliveTin missing authorization in ValidateArgumentType APIlowCVSS 3.7EPSS 0.4%
- CVE-2025-50946: GO-2025-3886 - OliveTin OS Command Injection vulnerability in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 1.3%
- CVE-2026-31817: GO-2026-4670 - OliveTin's unsafe parsing of UniqueTrackingId can be used to write files in github.com/OliveTin/OliveTinlowCVSS 3.1EPSS 0.9%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-olivetin-olivetin.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/OliveTin/OliveTin (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-olivetin-olivetin, 26 September 2026.