Sceawere

Vulnerability Detail

CVE-2026-76993UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PentestGPT Web-Page Crawling Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5
Creation Date
3h ago
Vendor
GreyDGL
Product
PentestGPT
Attack Type
Injection
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned".

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.0",
  "pubDate": "2026-08-20T15:18:40.013Z",
  "pubdate": "2026-08-20T15:18:40.013Z",
  "executiveSummary": "An injection vulnerability has been identified within GreyDGL PentestGPT up to version 1.0.0, specifically residing in the Web-Page Crawling component. This security flaw allows remote attackers to execute injection attacks against vulnerable deployments of the software. The vulnerability stems from improper handling or sanitization of input data supplied via the Traceback argument during the crawling process. Successful exploitation of this vulnerability can lead to unauthorized command or data injection, potentially compromising the integrity and confidentiality of the affected system. Despite the vulnerability being publicly disclosed, the associated exploitation vector is characterized by a high complexity level and difficult exploitability requirements, necessitating precise conditions or specific attacker capabilities to achieve successful exploitation. The project maintainers have addressed the reported GitHub issue by closing it with the label not planned, meaning an official vendor patch may not be immediately forthcoming. Consequently, organizations utilizing GreyDGL PentestGPT versions up to 1.0.0 face potential risk if exposed to untrusted web content or malicious crawling targets without adequate perimeter defenses or input validation controls.",
  "technicalDetails": "The vulnerability identified in GreyDGL PentestGPT up to 1.0.0 affects the Web-Page Crawling component, which is responsible for retrieving, processing, and parsing external web pages during penetration testing operations. The root cause of the vulnerability lies in the insecure handling and processing of the Traceback argument. When the application crawls web pages or processes error logs and debugging traces associated with the crawling functionality, improperly sanitized input passed through the Traceback parameter is processed by the underlying execution or parsing engine.\nThe attack vector is network-exposed, allowing a remote threat actor to initiate the attack without prior authentication or elevated privileges. Because the vulnerability involves the Web-Page Crawling mechanism, an attacker can manipulate the input payload—specifically targeting the Traceback argument—by hosting a malicious web page or intercepting network traffic to supply crafted data that the crawling component subsequently parses and evaluates.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies a deployment of GreyDGL PentestGPT up to 1.0.0 utilizing the vulnerable Web-Page Crawling feature. Second, the attacker prepares a malicious payload designed to exploit the injection vector, embedding it within data sources or responses that will be processed as part of the Traceback argument. Third, the attacker triggers the crawling operation against a controlled or manipulated endpoint. Fourth, as the application processes the retrieved content and handles execution errors or tracing routines, the unsanitized Traceback argument is interpreted by the component. Fifth, the injection payload executes within the context of the application, potentially leading to unauthorized command execution, data manipulation, or system compromise depending on the precise nature of the underlying injection flaw.\nAlthough the vulnerability carries a high complexity level and is classified as difficult to exploit, successful execution can result in severe post-exploitation impacts, including unauthorized code execution or system manipulation within the environment hosting the PentestGPT instance."
}
CVE-2026-76993: PentestGPT Web-Page Crawling Injection (MEDIUM Severity, CVSS: 5.0) - Sceawere