← Voltar à pesquisa de CVEs

CVE-2026-43990

JunoClaw

Descrição

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell-s run_command wrapped every agent-supplied command in -sh -c- / -cmd /C- and passed the full argument string to the shell-s parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command syntax. This vulnerability is fixed in 0.x.y-security-1.

CVSS 8.4EPSS 0.151%Risco 0.85
Ver fonte
Publicação
2026-05-12 17:16:20
Versões afetadas
cannotmatch
Tipo
Core software
Vetor
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H