CVE-2026-36044: n/a
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child_process.exec(). Because exec() spawns a shell, shell metacharacters in those values are interpreted by the host shell, resulting in arbitrary OS command execution with the privileges of the running process. NOTE: this is disputed by the Supplier because the report is about intended behavior, as explained in the Security Policy of the pensarai/apex GitHub repo.
AI Analysis
Technical Summary
The vulnerability in @pensar/apex (<= 0.0.58) involves unsafe construction of shell commands in the createSmartEnumerateTool() function located in src/core/agent/tools.ts. Unsanitized values from user-controllable inputs (extensions array and url parameter) are concatenated into a command string executed via Node.js child_process.exec(). Because exec() spawns a shell, any shell metacharacters in these inputs are interpreted by the host shell, enabling arbitrary OS command execution with the privileges of the process running the application. The supplier disputes the vulnerability report, claiming the behavior is intended and documented in their security policy. There is no vendor advisory or patch available at this time.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary operating system commands on the host with the privileges of the @pensar/apex process. This can lead to full system compromise depending on the privileges of the running process. The CVSS 3.1 base score is 8.8 (high), reflecting high impact on confidentiality, integrity, and availability, with low attack complexity and no privileges required but requiring user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the supplier disputes this as a vulnerability and no official fix or mitigation is provided, users should carefully review the security policy of the pensarai/apex GitHub repository and consider restricting or sanitizing inputs passed to the smart_enumerate tool. Avoid running the affected versions in high-risk environments until further guidance or patches are available.
CVE-2026-36044: n/a
Description
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child_process.exec(). Because exec() spawns a shell, shell metacharacters in those values are interpreted by the host shell, resulting in arbitrary OS command execution with the privileges of the running process. NOTE: this is disputed by the Supplier because the report is about intended behavior, as explained in the Security Policy of the pensarai/apex GitHub repo.
CVSS v3.1
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in @pensar/apex (<= 0.0.58) involves unsafe construction of shell commands in the createSmartEnumerateTool() function located in src/core/agent/tools.ts. Unsanitized values from user-controllable inputs (extensions array and url parameter) are concatenated into a command string executed via Node.js child_process.exec(). Because exec() spawns a shell, any shell metacharacters in these inputs are interpreted by the host shell, enabling arbitrary OS command execution with the privileges of the process running the application. The supplier disputes the vulnerability report, claiming the behavior is intended and documented in their security policy. There is no vendor advisory or patch available at this time.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary operating system commands on the host with the privileges of the @pensar/apex process. This can lead to full system compromise depending on the privileges of the running process. The CVSS 3.1 base score is 8.8 (high), reflecting high impact on confidentiality, integrity, and availability, with low attack complexity and no privileges required but requiring user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the supplier disputes this as a vulnerability and no official fix or mitigation is provided, users should carefully review the security policy of the pensarai/apex GitHub repository and consider restricting or sanitizing inputs passed to the smart_enumerate tool. Avoid running the affected versions in high-risk environments until further guidance or patches are available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-04-06T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a16f9d0e29bf47b50c0e775
Added to database: 05/27/2026, 14:04:00 UTC
Last enriched: 06/03/2026, 20:04:36 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 103
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.