← Back to CVE search

CVE-2026-43990

JunoClaw

Description

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell-s run_command wrapped every agent-supplied command in -sh -c- / -cmd /C- and passed the full argument string to the shell-s parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command syntax. This vulnerability is fixed in 0.x.y-security-1.

CVSS 8.4EPSS 0.151%Risk 0.85
View source
Published
2026-05-12 17:16:20
Affected versions
cannotmatch
Type
Core software
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H