THREAT OPS › Threat News › [GHSA] GHSA-2mw5-23gm-pccq (high) — OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
[GHSA] GHSA-2mw5-23gm-pccq (high) — OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
GHSA-2mw5-23gm-pccq Severity: high CVE: CVE-2026-73667
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
### Summary OpenChoreo Workflow Plane templates were vulnerable to OS command injection because some developer-controlled workflow parameters were interpolated directly into shell program text executed through sh -
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-73667cve
Original source: https://github.com/advisories/GHSA-2mw5-23gm-pccq