Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18593— vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox

Quick assessment

Affected
vxcontrol PentAGI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

VXControl PentAGI是VXControl团队开源的一款基于多智能体 AI 架构的自动化渗透测试平台,能够在隔离的 Docker 沙箱环境中自主执行漏洞扫描、攻击链开发与漏洞利用等复杂安全测试任务。 VXControl PentAGI 2.1.0及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Tool Management Protocol Handler组件中backend/pkg/templates/prompts/pentester.tmpl文件存在未知部分,执行操作可能导致沙箱问题

CVSS 5.6 · Medium EPSS 0.42% · P34

Affected Version Matrix 2

VendorProduct Version RangeStatus
vxcontrol PentAGI 2.0 affected
2.1.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18593

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
权限/沙箱问题
Source: CVE Program / CVE List V5
Vulnerability Title
VXControl PentAGI 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
VXControl PentAGI是VXControl团队开源的一款基于多智能体 AI 架构的自动化渗透测试平台,能够在隔离的 Docker 沙箱环境中自主执行漏洞扫描、攻击链开发与漏洞利用等复杂安全测试任务。 VXControl PentAGI 2.1.0及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Tool Management Protocol Handler组件中backend/pkg/templates/prompts/pentester.tmpl文件存在未知部分,执行操作可能导致沙箱问题
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
vxcontrol PentAGI 2.0 cpe:2.3:a:vxcontrol:pentagi:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-18593

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18593

请登录查看更多情报信息。

Proof of Concept for CVE-2026-18593 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18593

No comments yet


Leave a comment