๐Ÿ” CVE Alert

CVE-2026-55673

UNKNOWN 0.0

PowSyBl: Command Injection in LocalCommandExecutor-s

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without sufficient escaping. Attacker-controlled values reaching UnixLocalCommandExecutor.execute, WindowsLocalCommandExecutor.execute, LocalComputationManager.execute, ParallelLoadFlowActionSimulator.run, ActionSimulatorTool.run, AmplModelRunner.run, or AmplModelRunner.runAsync can break out of the intended command and execute arbitrary shell commands as the JVM user. The affected itools paths include action-simulator with task-count, security-analysis with external, and dynamic-security-analysis. Downstream CLI tools, libraries, REST front ends, and multi-tenant grid-analysis services that forward less-trusted contingency identifiers or computation parameters into these APIs can expose the injection remotely. This issue is fixed in version 7.2.2.

CWE CWE-78 CWE-88
Vendor powsybl
Product powsybl-core
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for powsybl powsybl-core

Be the first to know when new unknown vulnerabilities affecting powsybl powsybl-core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

powsybl / powsybl-core
< 7.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/powsybl/powsybl-core/security/advisories/GHSA-jqvf-j3ww-r8c7 github.com: https://github.com/powsybl/powsybl-core/pull/3973 github.com: https://github.com/powsybl/powsybl-core/commit/17461264d1d18f9bba43bb7855f251e9fa55a4db github.com: https://github.com/powsybl/powsybl-core/commit/7aa28d8c2492bbcd061585cb498acce72d5ed79a github.com: https://github.com/powsybl/powsybl-core/releases/tag/v7.2.2