


Perceptive Security
SOC/SIEM Consultancy

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to execSync() without proper sanitization, enabling remote code execution when the corpus parameter contains shell metacharacters. This issue has been patched in version 1.69.3.
Published:
3 mei 2026 om 22:00:00
Alert date:
4 mei 2026 om 18:09:25
Source:
nvd.nist.gov
Emerging Technologies, Web Technologies
A command injection vulnerability in Evolver, a GEP-powered self-evolving engine for AI agents, affects versions prior to 1.69.3. The vulnerability exists in the _extractLLM() function which constructs curl commands using string concatenation without proper sanitization. Attackers can execute arbitrary shell commands on the server by injecting shell metacharacters into the corpus parameter. The function passes unsanitized input to execSync(), enabling remote code execution. This critical security flaw has been patched in version 1.69.3.
Technical details
Mitigation steps:
Affected products:
Evolver
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42076, https://github.com/EvoMap/evolver/releases/tag/v1.69.3, https://github.com/EvoMap/evolver/security/advisories/GHSA-j5w5-568x-rq53
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
