CVE-2026-9453

A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en FoundDream miniclawd hasta 2d65665046e2222eeea76cafc8570ed546a8c125. Esto afecta a la función which del archivo /src/application/skills-loader.ts del componente SkillsLoader. Realizar una manipulación del argumento requires.bins resulta en inyección de comandos. El ataque puede iniciarse de forma remota. El exploit ahora es público y puede ser utilizado. Este producto utiliza un modelo de lanzamiento continuo para entregar actualizaciones continuas. Como resultado, la información de versión específica para las versiones afectadas o actualizadas no está disponible. El proyecto fue informado del problema con antelación a través de un informe de incidencias, pero aún no ha respondido.

25 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 13:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9453

Mitre link : CVE-2026-9453

CVE.ORG link : CVE-2026-9453


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')