


Perceptive Security
SOC/SIEM Consultancy

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffectiv…
Published:
30 March 2026 at 22:00:00
Alert date:
31 March 2026 at 17:08:47
Source:
nvd.nist.gov
Security Tools, Web Technologies
InfCode's terminal auto-execution module contains a critical command filtering vulnerability that completely bypasses its blacklist security mechanism. The vulnerability stems from an incomplete blocklist that fails to cover Windows PowerShell commands and a matching algorithm that cannot parse dynamic shell syntax including string concatenation, variable assignment, and quote interpolation. Attackers can exploit this by using simple syntax obfuscation to bypass command interception. When users import and view malicious files in the IDE, the system executes dangerous PowerShell commands without user confirmation, leading to arbitrary command execution and potential sensitive data leakage.
Technical details
Mitigation steps:
Affected products:
InfCode
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30309
https://github.com/Secsys-FDU/LLM-Tool-Calling-CVEs/issues/11
https://www.tokfinity.com/infcode
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
