Thesystem Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Thesystem version 1.0. This vulnerability allows unauthenticated attackers to execute arbitrary system commands by sending malicious input to the run_command endpoint. Exploitation involves POST requests with shell commands included in the command parameter, enabling unauthorized code execution on the server.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where Thesystem is running.

Reproduction

To reproduce this vulnerability, send a POST request to the run_command endpoint without authentication. Include a command in the command parameter. The server will execute the command and return the output.

Added: Feb 20, 2026, 11:30 PM
Updated: Feb 20, 2026, 11:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
3.2
threat
6.5
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.