OS Command Injection in yogeshojha reNgine affecting its listTargets Endpoint
CVE-2026-105487
Key Information:
- Vendor
Yogeshojha
- Status
- Vendor
- CVE Published:
- 6 October 2026
Badges
What is CVE-2026-105487?
A vulnerability exists in the yogeshojha reNgine, particularly within the listTargets Endpoint's subdomain_discovery function in tasks.py. This flaw allows for OS command injection through improper argument handling. Attackers can exploit this vulnerability remotely, leading to potential unauthorized command execution on the affected system. Public knowledge of this exploit heightens the urgency for remediation, with a pending pull request for a fix awaiting acceptance.
Affected Version(s)
reNgine 2.0
reNgine 2.1
reNgine 2.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
