CPE
A critical remote command injection vulnerability (CVE-2026-90617) exists in the MCP HTTP Server component of GH05TCREW PentestAgent, allowing unauthenticated attackers to execute arbitrary OS commands via the run_task function.