THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jqvf-j3ww-r8c7 (high) — PowSyBl Core has Command Injection in LocalCommandExecutor-s

[GHSA] GHSA-jqvf-j3ww-r8c7 (high) — PowSyBl Core has Command Injection in LocalCommandExecutor-s

medgithub_advisoriesPublished 2026-08-28

GHSA-jqvf-j3ww-r8c7 Severity: high CVE: CVE-2026-55673

PowSyBl Core has Command Injection in LocalCommandExecutor-s

### Impact

#### Description Both `AbstractLocalCommandExecutor` OS-dependent implementations are subject to **CWE-78** (OS Command Injection), with a secondary **CWE-88** (Argument Injection) concern via environment variables.

The local command executor build command strings via

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jqvf-j3ww-r8c7