Tugtainer Agent Command Execution Vulnerability Allowing Arbitrary Argument Injection
Vulnerability
A critical remote code execution vulnerability has been identified in the Tugtainer application, specifically in the Tugtainer agent component, versions prior to 1.15.1. This vulnerability allows arbitrary arguments to be injected via the 'POST api/command/run' endpoint.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the server where the Tugtainer agent is running.
Remediation
Users can upgrade to Tugtainer version 1.15.1 to address this vulnerability.
Added: Dec 29, 2025, 4:28 PM
Updated: Dec 29, 2025, 4:28 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
8.1remediation
7.7relevance
1.6threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
