CVE-2026-39054
EUVD-2026-3054715.05.2026, 15:16
Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution.
Awaiting analysis
This vulnerability is currently awaiting analysis.