THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2mw5-23gm-pccq (high) — OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

[GHSA] GHSA-2mw5-23gm-pccq (high) — OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

medgithub_advisoriesPublished 2026-09-02

GHSA-2mw5-23gm-pccq Severity: high CVE: CVE-2026-73667

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

### Summary OpenChoreo Workflow Plane templates were vulnerable to OS command injection because some developer-controlled workflow parameters were interpolated directly into shell program text executed through sh -

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2mw5-23gm-pccq