CVE-2026-8210
Received Received - Intake
Command Injection in aandrew-me TGPT Update Handler

Publication date: 2026-05-09

Last updated on: 2026-05-09

Assigner: VulDB

Description
A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of the component Update Handler. The manipulation leads to command injection. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-09
Last Modified
2026-05-09
Generated
2026-05-10
AI Q&A
2026-05-10
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
aandrew-me tgpt to 2.11.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker with local access to execute arbitrary commands on your system. This could lead to unauthorized actions such as modifying files, installing malware, or gaining further access to sensitive information. Since the exploit has been publicly disclosed, the risk of attack is increased.


Can you explain this vulnerability to me?

This vulnerability exists in the aandrew-me tgpt software up to version 2.11.1 on Linux and macOS systems. It affects the function helper.Update in the helper.go file within the Update Handler component. The issue allows an attacker with local access to perform command injection, meaning they can execute arbitrary commands on the affected system by manipulating this function.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart