CVE-2026-90621: OS Command Injection in ipa-lab HackingBuddyGPT
CVE-2026-90621 is an OS command injection vulnerability in ipa-lab HackingBuddyGPT versions 0.1 through 0.5.0. It affects the ssh_run_command function in the src/hackingBuddyGPT/extensions/ssh_run_command.py file. The vulnerability allows remote attackers to execute arbitrary OS commands. Exploit code is publicly available, but no vendor response or patch has been issued yet. The vulnerability has a medium severity rating with a CVSS 4.0 score of 5.3.
AI Analysis
Technical Summary
This vulnerability exists in ipa-lab HackingBuddyGPT up to version 0.5.0 in the ssh_run_command function. It allows remote attackers to perform OS command injection by manipulating input to this function. The flaw was reported early to the project, but no fix or official response has been provided. Public exploit code is available, increasing the risk of exploitation. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, and low to limited impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary operating system commands on the affected system. This can lead to unauthorized system control or data compromise. The impact is rated medium due to the limited scope of confidentiality, integrity, and availability impacts as per the CVSS vector. No known active exploitation in the wild has been reported.
Mitigation Recommendations
No official fix or patch is currently available, and the vendor has not responded to the issue report. Users should monitor the vendor's advisory channels for updates. Until a patch is released, avoid exposing the vulnerable ssh_run_command functionality to untrusted networks or users. Consider implementing network-level restrictions or other compensating controls to limit remote access to the affected component.
CVE-2026-90621: OS Command Injection in ipa-lab HackingBuddyGPT
Description
CVE-2026-90621 is an OS command injection vulnerability in ipa-lab HackingBuddyGPT versions 0.1 through 0.5.0. It affects the ssh_run_command function in the src/hackingBuddyGPT/extensions/ssh_run_command.py file. The vulnerability allows remote attackers to execute arbitrary OS commands. Exploit code is publicly available, but no vendor response or patch has been issued yet. The vulnerability has a medium severity rating with a CVSS 4.0 score of 5.3.
CVSS v4.0
Score 5.3medium
Affected software
ipa-lab
HackingBuddyGPT
pkg:github/ipa-lab/hackingBuddyGPTcpe:2.3:a:ipa-lab:hackingbuddygpt:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in ipa-lab HackingBuddyGPT up to version 0.5.0 in the ssh_run_command function. It allows remote attackers to perform OS command injection by manipulating input to this function. The flaw was reported early to the project, but no fix or official response has been provided. Public exploit code is available, increasing the risk of exploitation. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, and low to limited impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary operating system commands on the affected system. This can lead to unauthorized system control or data compromise. The impact is rated medium due to the limited scope of confidentiality, integrity, and availability impacts as per the CVSS vector. No known active exploitation in the wild has been reported.
Mitigation Recommendations
No official fix or patch is currently available, and the vendor has not responded to the issue report. Users should monitor the vendor's advisory channels for updates. Until a patch is released, avoid exposing the vulnerable ssh_run_command functionality to untrusted networks or users. Consider implementing network-level restrictions or other compensating controls to limit remote access to the affected component.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-12T20:22:34.583Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa8711955bf5e2cf5b48bee
Added to database: 09/14/2026, 22:11:37 UTC
Last enriched: 09/14/2026, 22:14:48 UTC
Last updated: 09/14/2026, 22:21:28 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.