{"id":"CVE-2026-63046","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63046","summary":"Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell\ncommands…","details":"Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell\ncommands via ExcuteLinux.exeCmd() with no filtering or whitelist\nvalidation. \n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1]/[2] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12151 .\n\n[2]  https://github.com/apache/inlong/pull/12155 .","published":"2026-08-21T09:16:40.083","modified":"2026-08-21T09:16:40.083","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread/2pgz70rz9ozfm7vm5c33po3yyspq846y"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T09:16:40.083"}}