THREAT OPS › Threat News › [GHSA] GHSA-xc5w-4v5w-7x65 (medium) — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
[GHSA] GHSA-xc5w-4v5w-7x65 (medium) — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
GHSA-xc5w-4v5w-7x65 Severity: medium CVE: CVE-2026-67438
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
### Summary OliveTin's checkShellArgumentSafety() function maintains a blocklist of argument types unsafe for Shell mode actions, but does not include regex:-prefixed types. Because regex: support was added independently via typeSafetyCheckRegex(), a
Indicators of compromise
- CVE-2026-67438cve
- ghcr.iodomain
Original source: https://github.com/advisories/GHSA-xc5w-4v5w-7x65