
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33623 is a Windows-only OS command injection vulnerability in PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser. The flaw exists in the orphaned Chrome cleanup path (internal/bridge/cleanup_windows.go) of PinchTab v0.8.4, where a PowerShell -Command string is constructed using a user-influenced needle derived from the instance profile path without properly neutralizing PowerShell metacharacters. It affects PinchTab versions prior to 0.8.5 (Go modules github.com/pinchtab/pinchtab and github.com/pinchtab/pinchtab/cmd/pinchtab). The vulnerability was published on March 22, 2026, and patched in v0.8.5. It carries a CVSS v3.1 base score of 7.2 (High) per Feedly threat intelligence, while the GitHub Advisory rates it 6.7 (Moderate) (GitHub Advisory, Feedly).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command) and CWE-400 (Uncontrolled Resource Consumption). In cleanup_windows.go, the findPIDsByPowerShell function builds a PowerShell command string via fmt.Sprintf, interpolating a needle value derived from the instance profile directory. While backslashes are escaped with strings.ReplaceAll, other PowerShell metacharacters — such as single quotes (') and statement separators (;) — are not sanitized, allowing injection of arbitrary PowerShell statements. The needle is sourced from the profile name supplied at instance launch via POST /instances/launch; v0.8.4 blocked path traversal characters (/, \, ..) but not PowerShell-specific metacharacters. Exploitation requires authenticated, administrative-equivalent API access to instance lifecycle endpoints — it is not an unauthenticated attack (GitHub Advisory, Security Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary PowerShell commands on the Windows host in the security context of the PinchTab process user, enabling full compromise of all data and processes accessible to that account. The attacker can establish persistence, exfiltrate sensitive data, or perform further lateral movement within the same user security boundary. Additionally, in environments with automatic instance restart behavior, the injected payload executes on every restart cycle, causing uncontrolled process spawning, resource exhaustion, and potential system instability — constituting a reliable denial-of-service condition alongside remote code execution (GitHub Advisory, Security Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands with specific payloads targeting the /instances/launch and /instances/{id}/stop API endpoints. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.026% (8th percentile), indicating low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
name field containing PowerShell metacharacters and injected commands, e.g., poc'; Start-Process calc; $x='./instances/launch with the malicious payload:curl -X POST http://[server-ip]:9867/instances/launch \
-H "Authorization: Bearer <TOKEN>" \
-H "Content-Type: application/json" \
-d '{"name": "poc'\'''; Start-Process calc; $x='\'''", "mode": "headless"}'findPIDsByPowerShell function with the attacker-controlled profile path as the needle:curl -X POST http://[server-ip]:9867/instances/<INSTANCE_ID>/stop \
-H "Authorization: Bearer <TOKEN>"/instances/launch with name fields containing PowerShell metacharacters (e.g., single quotes, semicolons, $, Start-Process, Invoke-Expression); POST requests to /instances/{id}/stop shortly after suspicious launch requests.name values containing special characters; PowerShell execution events in Windows Event Log (Event ID 4104 — Script Block Logging) triggered by the PinchTab process.powershell.exe executing commands beyond process enumeration, calc.exe, cmd.exe, or other binaries); repeated spawning of the same process in auto-restart environments.Upgrade PinchTab to version 0.8.5 or later, which resolves the vulnerability by avoiding interpolation of user-influenced values into PowerShell -Command strings (patch commit 25b3374) (Patch Commit). As interim mitigations: restrict API access to instance lifecycle endpoints (/instances/launch, /instances/stop) to trusted, minimal-privilege users and services only; run PinchTab under a dedicated service account with the least privileges necessary; and ensure the PinchTab HTTP API is not exposed beyond the local machine or a tightly controlled private network. Do not rely solely on profile name input validation as a defense — the fix must address the unsafe command construction pattern (GitHub Advisory, Security Advisory).
The vulnerability was reported by researcher "Yesuhei" and published by maintainer luigi-agosti on March 22, 2026. The patch commit (25b3374) also included broader security posture improvements to the PinchTab codebase, including enhanced warnings for non-default security-reducing configurations and improved documentation around the privileged nature of the dashboard, API, and MCP server control surfaces. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified (GitHub Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."