CVE Watchtower

← Back to CVE List

CVE-2026-90621NVD

Description

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity Level
MEDIUM (6.3)
Published Date
14/09/2026
Last Modified
15/09/2026
Exploitation Status
????
EPSS Score
1.09% (percentile 63.8%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 6.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS v4 (4.0)
MEDIUM 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Weaknesses (CWE)

CWE-78 - OS Command InjectionCWE-77 - Command Injection

Affected & Patched Versions

ProductAffected VersionsPatched Version
ipa-lab HackingBuddyGPT0.1, 0.2, 0.3, 0.4, 0.5.0N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.