


Perceptive Security
SOC/SIEM Consultancy

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows att…
Published:
3 May 2026 at 22:00:00
Alert date:
4 May 2026 at 18:09:25
Source:
nvd.nist.gov
Emerging Technologies, Web Technologies
A command injection vulnerability in Evolver, a GEP-powered self-evolving engine for AI agents, affects versions prior to 1.69.3. The vulnerability exists in the _extractLLM() function which constructs curl commands using string concatenation without proper sanitization. Attackers can execute arbitrary shell commands on the server by injecting shell metacharacters into the corpus parameter. The function passes unsanitized input to execSync(), enabling remote code execution. This critical security flaw has been patched in version 1.69.3.
Technical details
Mitigation steps:
Affected products:
Evolver
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42076
https://github.com/EvoMap/evolver/releases/tag/v1.69.3
https://github.com/EvoMap/evolver/security/advisories/GHSA-j5w5-568x-rq53
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
