CRITICALGo →
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
Affected packages
- github.com/OliveTin/OliveTin
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 1.00%
- EPSS percentile
- 59.3%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 59%.
Sources
- https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65
- https://nvd.nist.gov/vuln/detail/CVE-2026-67438
- https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232
- https://github.com/OliveTin/OliveTin
- https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0
Structured record: https://osv.dev/vulnerability/GHSA-xc5w-4v5w-7x65
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta