Olivetin is a focused task-execution and automation tool that exposes a command-interface to authorized users, concentrating its vulnerability exposure in a single product across a relatively narrow but notably prominent deployment footprint. The recurring weakness classes—improper access control, OS command injection, missing and incorrect authorization, and uncontrolled resource consumption—reflect the inherent risks of a system that parses and executes user-supplied commands, and vulnerabilities here carry a meaningful share that reach serious severity. Defenders deploying this tool should enforce strict network isolation, apply role-based access controls at the application layer, and treat input validation and authorization logic as critical hardening points; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Olivetin over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27626CRITICAL OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) | Feb 25, 2026 | 9.9 | 33 | NO | NO |
CVE-2026-30223HIGH OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local R | Mar 6, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-31817HIGH OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk. | Mar 10, 2026 | 8.5 | 28 | NO | NO |
CVE-2026-28790HIGH OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through K | Mar 5, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-28789HIGH OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 | Mar 5, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-28342HIGH OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive | Mar 5, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-50946MEDIUM OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go. | Aug 13, 2025 | 6.5 | 23 | NO | NO |
CVE-2026-32102MEDIUM OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to auth | Mar 11, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-30233MEDIUM OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization flaw in OliveTin allows authenticated users with view: false p | Mar 6, 2026 | 4.3 | 18 | NO | NO |
CVE-2026-30225MEDIUM OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low | Mar 6, 2026 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Olivetin.
Media articles that mention a CVE ID that affects a product developed by Olivetin — matched by CVE ID, not by vendor name.