Vulnerability  ·  2026-09-15

PentestAgent MCP HTTP server — OS command injection via run_task

VulnerabilityHigh impactGlobalCVE-2026-90617
PentestAgent is a niche single-author agentic pentesting tool; command injection in its MCP tool-invocation path is a textbook agent-tool RCE, but low current deployment breadth limits blast radius versus the HexStrike/PraisonAI findings.
The run_task function of the MCP HTTP Server component (interface/main.py) is vulnerable to OS command injection, remotely exploitable per the CVE record.
GH05TCREW PentestAgent (up to commit cf882dabea3ed91cef016cdd115e5426315665a2)
No patch confirmed at time of publication; avoid exposing the PentestAgent MCP HTTP server to untrusted input.
NVD CVE-2026-90617PentestAgent GitHub repository
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →