{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-55673/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:powsybl:powsybl_computation_local:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-55673"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["powsybl-computation-local (\u003c= 7.2.1)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-55673","command-injection","java","powsybl"],"_cs_type":"advisory","_cs_vendors":["PowSyBl"],"content_html":"\u003cp\u003ePowSyBl Core, specifically the \u003ccode\u003epowsybl-computation-local\u003c/code\u003e package versions 7.2.1 and earlier, contains critical command injection vulnerabilities (CWE-78) and argument injection (CWE-88) flaws. The library constructs shell command strings using insecure concatenation methods before passing them to the underlying operating system shell (\u003ccode\u003ebash -c\u003c/code\u003e on Unix/Linux, \u003ccode\u003ecmd /c\u003c/code\u003e on Windows).\u003c/p\u003e\n\u003cp\u003eThe vulnerability is exposed through public APIs in classes like \u003ccode\u003eUnixLocalCommandExecutor\u003c/code\u003e, \u003ccode\u003eWindowsLocalCommandExecutor\u003c/code\u003e, and \u003ccode\u003eLocalComputationManager\u003c/code\u003e, as well as several itools commands including \u003ccode\u003eaction-simulator\u003c/code\u003e and \u003ccode\u003esecurity-analysis\u003c/code\u003e. Because the library does not properly sanitize input parameters or environment variables, an attacker providing input to these APIs can escape the intended command sequence and execute arbitrary shell instructions with the privileges of the JVM process. This poses a significant risk to downstream services, such as REST front-ends or multi-tenant grid analysis platforms that process external inputs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the JVM user. This includes full system access, unauthorized file operations (read/write/execute), process spawning, and data exfiltration. The impact is elevated for services that expose these computation parameters to untrusted users, enabling remote code execution without the attacker needing to interact with the PowSyBl codebase directly.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ecom.powsybl:powsybl-computation-local\u003c/code\u003e to version 7.2.2 or higher immediately to address CVE-2026-55673.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, implement strict input validation for all user-provided arguments in the application layer, forbidding shell metacharacters such as ';', '|', '\u0026amp;', '$', and others identified in the official advisory for Unix and Windows systems.\u003c/li\u003e\n\u003cli\u003eAudit applications that integrate \u003ccode\u003epowsybl-computation-local\u003c/code\u003e to determine if they pass untrusted input to any of the vulnerable public methods, including \u003ccode\u003eLocalComputationManager.execute()\u003c/code\u003e or the \u003ccode\u003eitools\u003c/code\u003e command-line utilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:15:18Z","date_published":"2026-08-28T21:15:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-powsybl-command-injection/","summary":"PowSyBl Core is vulnerable to OS command and argument injection (CVE-2026-55673) via unsanitized shell concatenation in its local command execution components, allowing unauthenticated remote command execution.","title":"Command Injection Vulnerability in PowSyBl Core","url":"https://feed.craftedsignal.io/briefs/2026-08-powsybl-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-55673","version":"https://jsonfeed.org/version/1.1"}