<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-90618 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-90618/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 03:29:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-90618/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in GH05TCREW PentestAgent</title><link>https://feed.craftedsignal.io/briefs/2026-09-14-cve-2026-90617/</link><pubDate>Mon, 14 Sep 2026 03:29:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-14-cve-2026-90617/</guid><description>A critical remote command injection vulnerability (CVE-2026-90617) exists in the MCP HTTP Server component of GH05TCREW PentestAgent, allowing unauthenticated attackers to execute arbitrary OS commands via the run_task function.</description><content:encoded><![CDATA[<p>CVE-2026-90617 is a remote OS command injection vulnerability residing in the MCP HTTP Server component of the GH05TCREW PentestAgent, specifically within the <code>run_task</code> function of <code>interface/main.py</code>. The vulnerability affects all versions of PentestAgent up to commit <code>cf882dabea3ed91cef016cdd115e5426315665a2</code>. Given that this tool is designed for penetration testing purposes, the exposure of a remote RCE vulnerability is significant. An unauthenticated remote attacker can supply malicious input that is improperly sanitized before being passed to the underlying operating system shell. As the project utilizes a rolling release strategy and the fix is currently an unmerged pull request, users must monitor the project repository for the final patch. This flaw is actively being discussed in public forums, increasing the risk of exploitation by unauthorized actors against environments where PentestAgent is deployed.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthenticated remote code execution with the privileges of the PentestAgent service. In a typical penetration testing environment, this could lead to the full compromise of the testing host, exposure of sensitive credentials, internal network reconnaissance, and lateral movement. The lack of a stable versioned release makes tracking vulnerable instances challenging, and the nature of the tool suggests that compromised instances may hold high-value target information.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize monitoring for any network activity involving the MCP HTTP Server component of PentestAgent. Given the lack of a formal release, monitor the GH05TCREW repository for the merge of the fix associated with CVE-2026-90617. Until the fix is applied, restrict access to the PentestAgent interface to trusted IP addresses only, using firewall rules or network segmentation to prevent external access.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>cve</category><category>pentest-tool</category><category>cve-2026-90618</category><category>command-injection</category><category>rce</category></item></channel></rss>