OS Command Injection Vulnerability in webgjc web_robot by webgjc
CVE-2026-90492
5.3MEDIUM
What is CVE-2026-90492?
A security flaw exists in the webgjc web_robot versions 2.4.0, 2.5.0, and 2.8.0, where the function controller_listen/controller_recover in the file py/web.py is susceptible to OS command injection. By manipulating the 'case_name' argument, an attacker can execute arbitrary commands on the server remotely. This vulnerability has been publicly disclosed, indicating that it may be actively exploited by attackers. The vendor was informed prior to the public disclosure but has not provided a response.
Affected Version(s)
web_robot 2.4.0
web_robot 2.5.0
web_robot 2.8.0
