CVE-2026-33623: 
vulnerability analysis and mitigation

Overview

CVE-2026-33623 is a Windows-only OS command injection vulnerability in PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser. The flaw exists in the orphaned Chrome cleanup path (internal/bridge/cleanup_windows.go) of PinchTab v0.8.4, where a PowerShell -Command string is constructed using a user-influenced needle derived from the instance profile path without properly neutralizing PowerShell metacharacters. It affects PinchTab versions prior to 0.8.5 (Go modules github.com/pinchtab/pinchtab and github.com/pinchtab/pinchtab/cmd/pinchtab). The vulnerability was published on March 22, 2026, and patched in v0.8.5. It carries a CVSS v3.1 base score of 7.2 (High) per Feedly threat intelligence, while the GitHub Advisory rates it 6.7 (Moderate) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command) and CWE-400 (Uncontrolled Resource Consumption). In cleanup_windows.go, the findPIDsByPowerShell function builds a PowerShell command string via fmt.Sprintf, interpolating a needle value derived from the instance profile directory. While backslashes are escaped with strings.ReplaceAll, other PowerShell metacharacters — such as single quotes (') and statement separators (;) — are not sanitized, allowing injection of arbitrary PowerShell statements. The needle is sourced from the profile name supplied at instance launch via POST /instances/launch; v0.8.4 blocked path traversal characters (/, \, ..) but not PowerShell-specific metacharacters. Exploitation requires authenticated, administrative-equivalent API access to instance lifecycle endpoints — it is not an unauthenticated attack (GitHub Advisory, Security Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary PowerShell commands on the Windows host in the security context of the PinchTab process user, enabling full compromise of all data and processes accessible to that account. The attacker can establish persistence, exfiltrate sensitive data, or perform further lateral movement within the same user security boundary. Additionally, in environments with automatic instance restart behavior, the injected payload executes on every restart cycle, causing uncontrolled process spawning, resource exhaustion, and potential system instability — constituting a reliable denial-of-service condition alongside remote code execution (GitHub Advisory, Security Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands with specific payloads targeting the /instances/launch and /instances/{id}/stop API endpoints. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.026% (8th percentile), indicating low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain API credentials: Acquire a valid API bearer token with administrative-equivalent access to the PinchTab instance lifecycle endpoints on a Windows host running PinchTab v0.8.4.
  2. Craft malicious profile name: Construct a JSON payload with a profile name field containing PowerShell metacharacters and injected commands, e.g., poc'; Start-Process calc; $x='.
  3. Launch instance with crafted name: Send a POST request to /instances/launch with the malicious payload:
curl -X POST http://[server-ip]:9867/instances/launch \
  -H "Authorization: Bearer <TOKEN>" \
  -H "Content-Type: application/json" \
  -d '{"name": "poc'\'''; Start-Process calc; $x='\'''", "mode": "headless"}'
  1. Record the returned instance ID from the response for use in the next step.
  2. Trigger the cleanup routine: Send a POST request to stop the instance, which invokes the vulnerable findPIDsByPowerShell function with the attacker-controlled profile path as the needle:
curl -X POST http://[server-ip]:9867/instances/<INSTANCE_ID>/stop \
  -H "Authorization: Bearer <TOKEN>"
  1. Achieve arbitrary command execution: The injected PowerShell statement executes on the Windows host as the PinchTab process user. In auto-restart environments, the payload re-executes on each restart cycle (Security Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Authenticated POST requests to /instances/launch with name fields containing PowerShell metacharacters (e.g., single quotes, semicolons, $, Start-Process, Invoke-Expression); POST requests to /instances/{id}/stop shortly after suspicious launch requests.
  • Logs: PinchTab API access logs showing instance launch requests with anomalous name values containing special characters; PowerShell execution events in Windows Event Log (Event ID 4104 — Script Block Logging) triggered by the PinchTab process.
  • Process: Unexpected child processes spawned by the PinchTab Go process (e.g., powershell.exe executing commands beyond process enumeration, calc.exe, cmd.exe, or other binaries); repeated spawning of the same process in auto-restart environments.
  • File System: New files, scripts, or scheduled tasks created under the Windows user profile of the account running PinchTab; unexpected registry run keys or startup entries associated with the PinchTab service account (Security Advisory).

Mitigation and workarounds

Upgrade PinchTab to version 0.8.5 or later, which resolves the vulnerability by avoiding interpolation of user-influenced values into PowerShell -Command strings (patch commit 25b3374) (Patch Commit). As interim mitigations: restrict API access to instance lifecycle endpoints (/instances/launch, /instances/stop) to trusted, minimal-privilege users and services only; run PinchTab under a dedicated service account with the least privileges necessary; and ensure the PinchTab HTTP API is not exposed beyond the local machine or a tightly controlled private network. Do not rely solely on profile name input validation as a defense — the fix must address the unsafe command construction pattern (GitHub Advisory, Security Advisory).

Community reactions

The vulnerability was reported by researcher "Yesuhei" and published by maintainer luigi-agosti on March 22, 2026. The patch commit (25b3374) also included broader security posture improvements to the PinchTab codebase, including enhanced warnings for non-default security-reducing configurations and improved documentation around the privileged nature of the dashboard, API, and MCP server control surfaces. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified (GitHub Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management