THREATOPS
THREAT OPSThreat News › O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

lowfulldisclosurePublished 2026-09-04

<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> O-CMS version 1.0.0 contains an authenticated OS command injection<br /> vulnerability in the AI CLI configuration functionality. An authenticated<br /> attacker with sufficient privileges can supply shell metacharacters and<br /> additional commands through the ai_cli_script parameter of<br /> /admin/settings/save.<br /> <br /> When the con

Original source: https://seclists.org/fulldisclosure/2026/Sep/28