PatchSiren

Tokfinity CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Tokfinity CVE published 2026-03-31

CVE-2026-30309

CVE-2026-30309 is a high-severity vulnerability in InfCode's terminal auto-execution module, allowing for arbitrary command execution or sensitive data leakage due to its ineffective blacklist security mechanism. The module fails to cover native high-risk commands in Windows PowerShell and lacks dynamic semantic parsing, enabling malicious commands to bypass interception through simple syntax obfuscation. [truncated]