CyberRota Analysis
AI-GeneratedA command injection vulnerability exists in the classify_command_risk function of nearai ironclaw versions up to 0.29.1, allowing remote attackers to manipulate commands. This could lead to unauthorized command execution, posing a risk to systems running the affected software. Organizations using this software should prioritize applying the provided patch to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.