CVE-2026-76993CWE-707CWE-74

CVE-2026-76993

Medium · published August 20, 2026

CVSS v3.1
5.0
EPSS
0%
Percentile
13.0
In the wild
Unconfirmed
What it is

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned".

The record
Technical detail
CVSS v3.1
5.0 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS v4.0
2.3 · CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00224 · 13.0th percentile
Weaknesses
CWE-707 · Improper Neutralization; CWE-74 · Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Published
2026-08-20T19:18Z
References (7)
EPSS history
Timeline
  • 20 AUG 14:30Z
    GreyDGL PentestGPT Web-Page Crawling injection
    cvelistv5