Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39054

Опубликовано: 15 мая 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution.

EPSS

Процентиль: 71%
0.01414
Низкий

7.3 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.3
github
4 месяца назад

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution.

EPSS

Процентиль: 71%
0.01414
Низкий

7.3 High

CVSS3

Дефекты

CWE-77