OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-51858

CRITICAL · CVSS 9.8 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in camel-ai versions 0.2.91a1, 0.2.91a2, and 0.2.91a3 allows for prompt-driven shell command execution through the TerminalToolkit.shell_exec function, which lacks an approval boundary. This could lead to unauthorized command execution, posing a significant risk to systems using these versions. Organizations utilizing affected versions should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51858
Severity
CRITICAL
CVSS
9.8
EPSS
0.50%

Original NVD Description

In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.