top of page
perceptive_background_267k.jpg

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffectiv…

Published:

30 maart 2026 om 22:00:00

Alert date:

31 maart 2026 om 17:08:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Web Technologies

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that completely bypasses its blacklist security mechanism. The vulnerability stems from an incomplete blocklist that fails to cover Windows PowerShell commands and a matching algorithm that cannot parse dynamic shell syntax including string concatenation, variable assignment, and quote interpolation. Attackers can exploit this by using simple syntax obfuscation to bypass command interception. When users import and view malicious files in the IDE, the system executes dangerous PowerShell commands without user confirmation, leading to arbitrary command execution and potential sensitive data leakage.

Technical details

Mitigation steps:

Affected products:

InfCode

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page