Command Injection Affecting github.com/jmpsec/osctrl/cmd/admin package, versions <0.5.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.9% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMJMPSECOSCTRLCMDADMIN-15369741
  • published3 Mar 2026
  • disclosed27 Feb 2026
  • creditLeon Johnson, Kwangyun Keum

Introduced: 27 Feb 2026

CVE-2026-28279  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade github.com/jmpsec/osctrl/cmd/admin to version 0.5.0 or higher.

Overview

Affected versions of this package are vulnerable to Command Injection in the osctrl-admin environment configuration. An attacker can execute arbitrary shell commands on every endpoint that enrolls using a compromised environment by injecting commands into the hostname parameter, which are then embedded in enrollment scripts and executed with elevated privileges before agent installation. This enables actions such as backdoor installation, credential exfiltration, and full endpoint compromise.

References

CVSS Base Scores

version 4.0
version 3.1