NVD/NISTCVE-2026-31246
GPT-Pilot Flaw Enables Command Injection
PublishedMay 11, 2026 at 4:17 PM·low
What happened
A command injection vulnerability (CVE-2026-31246) in the AI coding tool GPT-Pilot lets attackers swap in malicious shell commands when users confirm or edit commands during project execution, leading to remote code execution. Developers running GPT-Pilot on their machines are at risk, especially in shared or automated environments. Update to a patched commit once available, and avoid running untrusted projects or blindly accepting suggested commands.
Tags
#gpt-pilot#command-injection#cve#rce
Source reference
https://github.com/Pythagora-io/gpt-pilot ↗See how Fortify maps this threat to your compliance posture.
14-day free trial · no credit card · HIPAA, SOC 2, ISO 27001, GDPR
Sign Up →