CVE-2026-5584
קריטית 9.8
תיאור (מקור, אנגלית)
A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
5.5 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-24/9/2026
- CWE
- CWE-74, CWE-94
מוצרים מושפעים
fosowl: agenticseek
קישורים
- https://github.com/August829/CVEP/issues/29 Issue Tracking
- https://vuldb.com/submit/784052 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/355383 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/355383/cti Permissions RequiredVDB Entry