LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-30310

CVE-2026-30310 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 1, 2026

Sixth - Command Injection

Published: March 31, 2026Updated: April 1, 2026Remote Exploitable

Overview

Sixth contains a command injection caused by prompt injection attacks misleading the model to misclassify malicious commands as safe, letting attackers execute arbitrary terminal commands without user approval.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Attackers can execute arbitrary terminal commands, potentially leading to full system compromise.

Mitigation

Update to the latest version with improved command classification and user approval mechanisms.

Details

CVE ID
CVE-2026-30310
Severity
Critical
CVSS Score
9.8
Type
command_injection
Status
unconfirmed

CWE

  • CWE-77

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H