Fortify
← All intel
NVD/NISTCVE-2026-31246

GPT-Pilot Flaw Enables Command Injection

PublishedMay 11, 2026 at 4:17 PM·low

What happened

A command injection vulnerability (CVE-2026-31246) in the AI coding tool GPT-Pilot lets attackers swap in malicious shell commands when users confirm or edit commands during project execution, leading to remote code execution. Developers running GPT-Pilot on their machines are at risk, especially in shared or automated environments. Update to a patched commit once available, and avoid running untrusted projects or blindly accepting suggested commands.

Tags

#gpt-pilot#command-injection#cve#rce

Source reference

https://github.com/Pythagora-io/gpt-pilot

See how Fortify maps this threat to your compliance posture.

14-day free trial · no credit card · HIPAA, SOC 2, ISO 27001, GDPR

Sign Up →