CVE-2025-67511

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.
Configurations

No configuration.

History

11 Dec 2025, 18:16

Type Values Removed Values Added
References
  • () https://www.hacktivesecurity.com/blog/2025/12/10/cve-2025-67511-tricking-a-security-ai-agent-into-pwning-itself -

11 Dec 2025, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 00:16

Updated : 2025-12-12 15:18


NVD link : CVE-2025-67511

Mitre link : CVE-2025-67511

CVE.ORG link : CVE-2025-67511


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')