CVE-2026-108890 | BlackBeltTechnology pi-agent-dashboard up to 0.8.0 Terminal terminal-handler.ts terminalManager.spawn cwd improper authorization (Issue 625)
A vulnerability classified as critical has been found in BlackBeltTechnology pi-agent-dashboard up to 0.8.0. Affected by this issue is the function terminalManager.spawn of the file packages/server/src/browser-handlers/terminal-handler.ts of the component Terminal Handler. The manipulation of the argument cwd leads to improper authorization.
This vulnerability is documented as CVE-2026-108890. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to install a patch to address this issue.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.VulDB Recent EntriesRead More