SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81562

MEDIUM · CVSS 5.3 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the execSync function of the AlexGladkov claude-in-mobile version 3.10.2, allowing local attackers to execute arbitrary OS commands. This flaw poses a medium risk, and organizations using this version should prioritize upgrading to 3.10.3 to mitigate potential exploitation, as the exploit has been publicly released. Immediate action is recommended for users of the affected software to enhance their security posture.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81562
Severity
MEDIUM
CVSS
5.3
EPSS
0.63%

Original NVD Description

A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.10.3 is able to mitigate this issue. The patch is named a86d9e55694c98a122943eeff859461d0b9aa6d6. It is suggested to upgrade the affected component.