AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18980

MEDIUM · CVSS 6.3 EPSS 1.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the classify_command_risk function of nearai ironclaw versions up to 0.29.1, allowing remote attackers to manipulate commands. This could lead to unauthorized command execution, posing a risk to systems running the affected software. Organizations using this software should prioritize applying the provided patch to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18980
Severity
MEDIUM
CVSS
6.3
EPSS
1.33%

Original NVD Description

A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.