← Späť na vyhľadávanie CVE

CVE-2026-43990

JunoClaw

Popis

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell-s run_command wrapped every agent-supplied command in -sh -c- / -cmd /C- and passed the full argument string to the shell-s parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command syntax. This vulnerability is fixed in 0.x.y-security-1.

CVSS 8.4EPSS 0.151%Riziko 0.85
Zobraziť zdroj
Zverejnené
2026-05-12 17:16:20
Dotknuté verzie
cannotmatch
Typ
Core software
Vektor
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H