Shell Command Injection Risk in OliveTin by OliveTin
CVE-2026-67438
6.6MEDIUM
What is CVE-2026-67438?
OliveTin has a vulnerability that allows access to predefined shell commands via a web interface. The flaw lies in the checkShellArgumentSafety function, which fails to consider regex: custom argument types as unsafe during Shell mode actions. This oversight allows malicious input that bypasses the type safety checks, subsequently being executed through sh -c command strings. It is crucial for users to update to version 3000.17.0, where this issue has been addressed.
Affected Version(s)
OliveTin >= 3000.2.0, < 3000.17.0
