Autonomous Hacking Agent Vulnerability in Decepticon by BitterSecurity
CVE-2026-61732

10CRITICAL

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-61732?

The Decepticon hacking agent from BitterSecurity is susceptible to a vulnerability due to improper handling of special-token literals in LLM messages generated during web crawls. In versions before 1.1.17, the system wraps results of agent reconnaissance without filtering these literals, allowing an attacker to manipulate the process. This can result in an attacker executing arbitrary commands within the controlled environment, as the system erroneously trusts these inputs as legitimate commands. The issue has been addressed in version 1.1.17.

Affected Version(s)

Decepticon < 1.1.17

decepticon-core < 1.1.17

decepticon-sdk < 1.1.17

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.