← Πίσω στην αναζήτηση CVE

CVE-2026-43990

JunoClaw

Περιγραφή

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell-s run_command wrapped every agent-supplied command in -sh -c- / -cmd /C- and passed the full argument string to the shell-s parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command syntax. This vulnerability is fixed in 0.x.y-security-1.

CVSS 8.4EPSS 0.151%Κίνδυνος 0.85
Προβολή πηγής
Δημοσίευση
2026-05-12 17:16:20
Επηρεαζόμενες εκδόσεις
cannotmatch
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H