hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-68766 is a command injection vulnerability in hashcat that exploits insufficient input validation when parsing restore files. The vulnerability allows attackers to inject malicious command-line options—specifically output redirection flags like --outfile and --potfile-path—through crafted restore files. By redirecting hashcat's output to arbitrary file locations, attackers can write attacker-controlled content to sensitive files, particularly shell startup files (.bashrc, .profile, etc.), leading to arbitrary code execution with the privileges of the user running hashcat. This affects any organization using hashcat for password cracking or security testing, especially in environments where restore files may come from untrusted sources or where multiple users share hashcat installations.
While CVE-2026-68766 does not map to specific MITRE ATT&CK techniques in the current framework, Casky.ai's security skills would detect attack patterns consistent with T1059 (Command and Scripting Interpreter), T1222 (File and Directory Permissions Modification), and T1547 (Boot or Logon Initialization Scripts). A practitioner using Casky would observe detection patterns indicating file write operations to unexpected locations, suspicious restore file modifications, and output being redirected to shell configuration directories. The platform's extended reasoning capabilities would correlate the restore file parsing behavior with post-exploitation persistence mechanisms, surfacing the attack chain from initial file injection through code execution. Security teams would see alerts highlighting the risk of untrusted restore files and recommendations to implement strict file input validation and restrict hashcat's output permissions.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-68766. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation