Tugtainer Agent Command Execution Vulnerability Allowing Arbitrary Argument Injection

Vulnerability

A critical remote code execution vulnerability has been identified in the Tugtainer application, specifically in the Tugtainer agent component, versions prior to 1.15.1. This vulnerability allows arbitrary arguments to be injected via the 'POST api/command/run' endpoint.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where the Tugtainer agent is running.

Remediation

Users can upgrade to Tugtainer version 1.15.1 to address this vulnerability.

Added: Dec 29, 2025, 4:28 PM
Updated: Dec 29, 2025, 4:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.1
remediation
7.7
relevance
1.6
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.