github.com/jmpsec/osctrl
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/jmpsec/osctrlpage 1 of 1
- CVE-2026-28279HIGHCVSS 8.4EG 8.4✓ Fixed in 0.5.02026-02-26
osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell commands via the host…
- CVE-2026-28280HIGHCVSS 8.7EG 8.7✓ Fixed in 0.5.02026-02-26
osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exists in the `osctrl-admin` on-demand query list. A user with query-level permissions can inject arbitrary JavaScript via …
Check whether github.com/jmpsec/osctrl is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/jmpsec/osctrl CVEs against the assets you own.
Start Free Scan →