top of page
perceptive_background_267k.jpg

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows att…

Published:

3 mei 2026 om 22:00:00

Alert date:

4 mei 2026 om 18:09:25

Source:

nvd.nist.gov

Click to open the original link from this advisory

Emerging Technologies, Web Technologies

A command injection vulnerability in Evolver, a GEP-powered self-evolving engine for AI agents, affects versions prior to 1.69.3. The vulnerability exists in the _extractLLM() function which constructs curl commands using string concatenation without proper sanitization. Attackers can execute arbitrary shell commands on the server by injecting shell metacharacters into the corpus parameter. The function passes unsanitized input to execSync(), enabling remote code execution. This critical security flaw has been patched in version 1.69.3.

Technical details

Mitigation steps:

Affected products:

Evolver

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page