THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xc5w-4v5w-7x65 (medium) — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

[GHSA] GHSA-xc5w-4v5w-7x65 (medium) — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

highgithub_advisoriesPublished 2026-07-30

GHSA-xc5w-4v5w-7x65 Severity: medium CVE: CVE-2026-67438

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

### Summary OliveTin's checkShellArgumentSafety() function maintains a blocklist of argument types unsafe for Shell mode actions, but does not include regex:-prefixed types. Because regex: support was added independently via typeSafetyCheckRegex(), a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xc5w-4v5w-7x65