{"id":"GO-2026-4920","summary":"KubeAI: OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model pods in github.com/kubeai-project/kubeai","details":"KubeAI: OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model pods in github.com/kubeai-project/kubeai","aliases":["CVE-2026-34940","GHSA-324q-cwx9-7crr"],"modified":"2026-04-06T18:17:45.225053Z","published":"2026-04-06T17:49:27Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4920"},"references":[{"type":"ADVISORY","url":"https://github.com/kubeai-project/kubeai/security/advisories/GHSA-324q-cwx9-7crr"}],"affected":[{"package":{"name":"github.com/kubeai-project/kubeai","ecosystem":"Go","purl":"pkg:golang/github.com/kubeai-project/kubeai"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.23.2"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/kubeai-project/kubeai/internal/modelcontroller","symbols":["ModelReconciler.Reconcile","ollamaStartupProbeScript"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4920.json"}}],"schema_version":"1.7.5"}