CVE-2026-42076Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to execSync() without proper sanitization, enabling remote code execution when the corpus parameter contains shell metacharacters. This issue has been patched in version 1.69.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-13)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-04: 2Mentions · 2026-05-13: 3Technical Details · 2026-05-04: 2Technical Details · 2026-05-13: 205-0405-13
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-133
Disclosure2General1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42076 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Evolver is a GEP-powered self-evolving engine for AI agents.

    Post summary

    CVE-2026-42076 is disclosed as a critical vulnerability with a CVSS score of 9.8, but no exploitation, PoC, patch, or false positive information is provided.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-42076 · 9.8 → 1.69.3 CVE: CVE-2026-42076 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑42076 as a critical vulnerability with a CVSS 3.1 score of 9.8, but does not provide any PoC, exploit code, active exploitation evidence, patch, or mitigation information.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42076-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The snippet only contains a URL to a research advisory and tags, offering no further details about the CVE.

    0000024
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42076 Command Injection Vulnerability in Evolver Prior to Version 1.69.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42076

    Post summary

    A command injection vulnerability (CVE‑2026‑42076) affecting Evolver versions before 1.69.3 has been disclosed, but no PoC, exploit, or mitigation details are provided.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42076 Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers… https://www.cve.org/CVERecord?id=CVE-2026-42076

    Post summary

    The text announces a command injection flaw in Evolver’s _extractLLM() function affecting versions prior to 1.69.3.

    00000121
    57.4K followersView on X

Explore more