
🚨 Critical - utcp-cli OS Command Injection → Unauthenticated RCE (CVE-2026-45369) _substitute_utcp_args in utcp-cli embeds user-controlled arguments straight into /bin/bash -c / powershell.exe calls without escaping, letting unauthenticated attackers inject shell metacharacters (;, |, &, backticks, $()) for full RCE (CVSS 10.0). Patch adds shlex.quote on Unix and PowerShell single-quoting on Windows. 👉 Affected: utcp-cli (pip) ≤ 1.1.1 | Upgrade to 1.1.2
Post summary
The post announces a critical command‑injection flaw in utcp-cli (CVE‑2026‑45369), provides technical details and CVSS score, and highlights the vendor’s patch that mitigates the issue.

