Web-Page Crawling Vulnerability in GreyDGL PentestGPT
CVE-2026-76993

2.3LOW

Key Information:

Vendor

Greydgl

Vendor
CVE Published:
20 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-76993?

A security vulnerability exists in GreyDGL's PentestGPT, specifically affecting the web-page crawling component. This flaw allows attackers to manipulate the Traceback argument, enabling remote code injection. Although the complexity of the exploit is considered high, its potential for exploitation can lead to significant risks. This vulnerability has been publicly disclosed and exists in versions of the product up to 1.0.0. Although the GitHub issue related to this vulnerability was closed with no planned remedy, it's crucial for users to remain vigilant and implement adequate security measures.

Affected Version(s)

PentestGPT 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ez-lbz (VulDB User)
VulDB CNA Team
.