Vendor
critical
advisory
@evomap/evolver Path Traversal Vulnerability Leads to RCE
2 rules 2 TTPsA path traversal vulnerability in `@evomap/evolver` allows a malicious A2A Hub to overwrite project files, leading to remote code execution when a user fetches a malicious skill.
@evomap/evolver
path-traversal
rce
evomap
2r
2t
critical
advisory
Evolver Remote Code Execution via Command Injection in `_extractLLM()`
2 rules 1 TTPA command injection vulnerability in the `_extractLLM()` function of the evolver application allows remote attackers to execute arbitrary shell commands by injecting shell metacharacters into the `corpus` parameter, leading to potential system compromise.
@evomap/evolver
command-injection
rce
evolver
2r
1t