216.73.216.226

CVE-2026-42076

· Published 04/05/2026 17:16 · Modified 04/05/2026 17:16

Labels: CVE-2026-42076 2026-05-04CVE-2026-42076CWE-78[email protected]

Essential information

Published
04/05/2026 17:16
Modified
04/05/2026 17:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to execSync() without proper sanitization, enabling remote code execution when the corpus parameter contains shell metacharacters. This issue has been patched in version 1.69.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
*(evolver) / *(1.68.*) cpe:2.3:a:*(evolver):*(1.68.*):*:*:*:*:*:*:*

References