{"id":"CVE-2026-75429","details":"PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer","modified":"2026-09-06T03:46:40.645623371Z","published":"2026-09-04T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75429.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://gist.github.com/unpredictable21/dbd1791294c9a77ad0ee3d4827073966"},{"type":"WEB","url":"https://github.com/PowerJob/PowerJob/blob/master/docker-compose.yml"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75429.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75429"},{"type":"PACKAGE","url":"https://github.com/PowerJob/PowerJob"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerjob/powerjob","events":[{"introduced":"0"},{"fixed":"332179de26b44f0a949f7594ce9f57ee26fb6b27"}],"database_specific":{"extracted_events":[{"introduced":"4.x"},{"fixed":"5.1.2"}],"source":"DESCRIPTION"}}],"versions":["v5.1.1","v5.1.0-bugfix","v5.1.0","v4.3.9","v4.3.8","v4.3.7","v4.3.6","v4.3.5","v4.3.4","v4.3.3","v4.3.2","v4.3.1","v4.3.0","v4.2.1","v4.2.0","v4.1.1","v4.1.0","v4.0.1","v4.0.0","v3.4.8","v3.4.7","v3.4.6","v3.4.5","v3.4.4","v3.4.3","v3.4.2","v3.4.1","v3.4.0-bugfix","v3.4.0","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.3","v3.2.2-bugfix","v3.2.2","v3.2.1","v3.2.0","v3.1.3","v3.1.2","v3.1.1","v3.1.0","v3.0.1","v3.0.0","v2.0.0","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75429.json"}}],"schema_version":"1.9.0"}