Tag
high
advisory
Emissary OS Command Injection Vulnerability (CVE-2026-35581)
2 rules 1 TTP 1 CVEEmissary, a P2P data-driven workflow engine, is vulnerable to OS command injection due to insufficient sanitization of the PLACE_NAME parameter in versions prior to 8.39.0, allowing for arbitrary command execution.
cve
command injection
emissary
2r
1t
1c
critical
advisory
Emissary Executrix OS Command Injection Vulnerability
2 rules 1 TTPA vulnerability in Emissary's Executrix class allows for arbitrary OS command execution by injecting shell metacharacters into the IN_FILE_ENDING or OUT_FILE_ENDING configuration values, leading to code execution within the JVM's security context.
Emissary
command-injection
executrix
ghsa-3p24-9x7v-7789
2r
1t