CVE-2026-30305 describes a critical OS command injection vulnerability in Syntx's command auto-approval module, allowing attackers to bypass its whitelist by embedding malicious commands within standard shell substitution syntax. Rated 9.8 CRITICAL, this flaw has a network attack vector and low attack complexity, enabling unauthenticated Remote Code Execution (RCE) with full impact on confidentiality, integrity, and availability. Although listed as "Hot List: Active," there is currently no public exploit code available, it is not in CISA's KEV catalog, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5.0CPE matchmatch criteria | cpe:2.3:a:orangecat:syntx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.