A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.
References
Configurations
No configuration.
History
06 Aug 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nearai/ironclaw/issues/4861 - | |
| References | () https://vuldb.com/submit/862542 - | |
| References | () https://vuldb.com/submit/862543 - | |
| References | () https://vuldb.com/submit/862544 - | |
| References | () https://vuldb.com/submit/862545 - | |
| References | () https://vuldb.com/submit/862546 - |
06 Aug 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-06 02:16
Updated : 2026-08-06 16:16
NVD link : CVE-2026-18980
Mitre link : CVE-2026-18980
CVE.ORG link : CVE-2026-18980
JSON object : View
Products Affected
No product.
