Command Injection Vulnerability in PowSyBl Framework by PowSyBl
CVE-2026-55673
What is CVE-2026-55673?
The PowSyBl framework, used for building power system-oriented software, is susceptible to command injection vulnerabilities prior to version 7.2.2. Both UnixLocalCommandExecutor and WindowsLocalCommandExecutor components improperly concatenate command arguments and environmental variables, enabling attackers to execute arbitrary shell commands. Received inputs that reach critical execution points within the APIs may lead to unintended command execution under the JVM user's privileges. Affected paths include 'action-simulator' and 'security-analysis'. The vulnerability is particularly severe in scenarios involving downstream CLI tools and multi-tenant grid-analysis services that might pass less-trusted data into the APIs.
Affected Version(s)
powsybl-core < 7.2.2
