{"id":"CVE-2026-67438","summary":"OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check","details":"OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument types as unsafe for Shell mode actions, allowing values that pass typeSafetyCheckRegex to be interpolated by wrapCommandInShell into an sh -c command string and enabling OS command injection. This issue is fixed in version 3000.17.0.","aliases":["GHSA-xc5w-4v5w-7x65"],"modified":"2026-07-31T03:49:06.881480578Z","published":"2026-07-29T20:53:09.524Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67438.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67438.json"},{"type":"ADVISORY","url":"https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67438"},{"type":"FIX","url":"https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/olivetin/olivetin","events":[{"introduced":"d54f2307c7ee690e9a1d7ef853ca53a617c8867f"},{"fixed":"995ff79736f2bccc364448a3ece84087b550b232"},{"fixed":"d0075a7a8d44028793ea3384b34062b940841f24"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"3000.2.0"},{"fixed":"3000.17.0"}]}}],"versions":["3000.16.2","3000.16.1","3000.16.0","3000.15.0","3000.14.0","3000.13.0","3000.11.1","3000.12.0","3000.11.4","3000.11.3","3000.11.2","3000.11.0","3000.10.2","3000.10.1","3000.10.0","3000.9.4","3000.9.1","3000.9.0","3000.8.0","3000.7.0","3000.6.0","3000.5.0","3000.4.0","3000.3.2","3000.3.1","3000.3.0","3000.2.1","3000.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67438.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}