OliveTin是OliveTin团队开源的一个Web应用。 OliveTin 3000.2.0版本至3000.17.0之前版本存在命令注入漏洞,该漏洞源于checkShellArgumentSafety函数未将regex自定义参数类型视为不安全,导致OS命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67437 | 7.5 HIGH | OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) |
| CVE-2026-67439 | 4.3 MEDIUM | OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output |
No comments yet