<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 22:24:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-263255</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263255</link>
      <description>EUVD-2026-263255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263255</guid>
    </item>
    <item>
      <title>fkie_cve-2025-67511</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-67511</link>
      <description>&lt;p&gt;Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is  available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is  available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-67511</guid>
    </item>
    <item>
      <title>GHSA-4c65-9gqf-4w8h — Cybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent tool</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4c65-9gqf-4w8h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cai-framework&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A command injection vulnerability is present in the function tool `run_ssh_command_with_credentials()` available to AI agents.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;This is the source code of the function tool `run_ssh_command_with_credentials()` ([code](https://github.com/aliasrobotics/cai/blob/0.5.9/src/cai/tools/command_and_control/sshpass.py#L20)):&lt;/p&gt;
&lt;p&gt;```python
@function_tool
def run_ssh_command_with_credentials(
        host: str,
        username: str,
        password: str,
        command: str,
        port: int = 22) -&amp;gt; str:
    &amp;#34;&amp;#34;&amp;#34;
    Execute a command on a remote host via SSH using password authentication.&lt;/p&gt;
&lt;p&gt;Args:
        host: Remote host address
        username: SSH username
        password: SSH password
        command: Command to execute on remote host
        port: SSH port (default: 22)&lt;/p&gt;
&lt;p&gt;Returns:
        str: Output from the remote command execution
    &amp;#34;&amp;#34;&amp;#34;
    # Escape special characters in password and command to prevent shell injection
    escaped_password = password.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    escaped_command = command.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    
    ssh_command = (
        f&amp;#34;sshpass -p &amp;#39;{escaped_password}&amp;#39; &amp;#34;
        f&amp;#34;ssh -o StrictHostKeyChecking=no &amp;#34;
        f&amp;#34;{username}@{host} -p {port} &amp;#34;
        f&amp;#34;&amp;#39;{escaped_command}&amp;#39;&amp;#34;
    )
    return run_command(ssh_command)&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;Note how only *password* and *command* inputs are escaped to prevent shell injection; while *username*, *host* and *port* values are left injectable.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Create an `index.html` file with t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cai-framework&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A command injection vulnerability is present in the function tool `run_ssh_command_with_credentials()` available to AI agents.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;This is the source code of the function tool `run_ssh_command_with_credentials()` ([code](https://github.com/aliasrobotics/cai/blob/0.5.9/src/cai/tools/command_and_control/sshpass.py#L20)):&lt;/p&gt;
&lt;p&gt;```python
@function_tool
def run_ssh_command_with_credentials(
        host: str,
        username: str,
        password: str,
        command: str,
        port: int = 22) -&amp;gt; str:
    &amp;#34;&amp;#34;&amp;#34;
    Execute a command on a remote host via SSH using password authentication.&lt;/p&gt;
&lt;p&gt;Args:
        host: Remote host address
        username: SSH username
        password: SSH password
        command: Command to execute on remote host
        port: SSH port (default: 22)&lt;/p&gt;
&lt;p&gt;Returns:
        str: Output from the remote command execution
    &amp;#34;&amp;#34;&amp;#34;
    # Escape special characters in password and command to prevent shell injection
    escaped_password = password.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    escaped_command = command.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    
    ssh_command = (
        f&amp;#34;sshpass -p &amp;#39;{escaped_password}&amp;#39; &amp;#34;
        f&amp;#34;ssh -o StrictHostKeyChecking=no &amp;#34;
        f&amp;#34;{username}@{host} -p {port} &amp;#34;
        f&amp;#34;&amp;#39;{escaped_command}&amp;#39;&amp;#34;
    )
    return run_command(ssh_command)&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;Note how only *password* and *command* inputs are escaped to prevent shell injection; while *username*, *host* and *port* values are left injectable.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Create an `index.html` file with t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4c65-9gqf-4w8h</guid>
    </item>
    <item>
      <title>PYSEC-2026-302 — Cybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent tool</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-302</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cai-framework&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A command injection vulnerability is present in the function tool `run_ssh_command_with_credentials()` available to AI agents.&lt;/p&gt;
&lt;p&gt;### Details
 
This is the source code of the function tool `run_ssh_command_with_credentials()` ([code](https://github.com/aliasrobotics/cai/blob/0.5.9/src/cai/tools/command_and_control/sshpass.py#L20)):
 
```python
@function_tool
def run_ssh_command_with_credentials(
        host: str,
        username: str,
        password: str,
        command: str,
        port: int = 22) -&amp;gt; str:
    &amp;#34;&amp;#34;&amp;#34;
    Execute a command on a remote host via SSH using password authentication.&lt;/p&gt;
&lt;p&gt;Args:
        host: Remote host address
        username: SSH username
        password: SSH password
        command: Command to execute on remote host
        port: SSH port (default: 22)&lt;/p&gt;
&lt;p&gt;Returns:
        str: Output from the remote command execution
    &amp;#34;&amp;#34;&amp;#34;
    # Escape special characters in password and command to prevent shell injection
    escaped_password = password.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    escaped_command = command.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    
    ssh_command = (
        f&amp;#34;sshpass -p &amp;#39;{escaped_password}&amp;#39; &amp;#34;
        f&amp;#34;ssh -o StrictHostKeyChecking=no &amp;#34;
        f&amp;#34;{username}@{host} -p {port} &amp;#34;
        f&amp;#34;&amp;#39;{escaped_command}&amp;#39;&amp;#34;
    )
    return run_command(ssh_command)
 
```&lt;/p&gt;
&lt;p&gt;Note how only *password* and *command* inputs are escaped to prevent shell injection; while *username*, *host* and *port* values are left injectable.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Create an `index.html` file wit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cai-framework&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A command injection vulnerability is present in the function tool `run_ssh_command_with_credentials()` available to AI agents.&lt;/p&gt;
&lt;p&gt;### Details
 
This is the source code of the function tool `run_ssh_command_with_credentials()` ([code](https://github.com/aliasrobotics/cai/blob/0.5.9/src/cai/tools/command_and_control/sshpass.py#L20)):
 
```python
@function_tool
def run_ssh_command_with_credentials(
        host: str,
        username: str,
        password: str,
        command: str,
        port: int = 22) -&amp;gt; str:
    &amp;#34;&amp;#34;&amp;#34;
    Execute a command on a remote host via SSH using password authentication.&lt;/p&gt;
&lt;p&gt;Args:
        host: Remote host address
        username: SSH username
        password: SSH password
        command: Command to execute on remote host
        port: SSH port (default: 22)&lt;/p&gt;
&lt;p&gt;Returns:
        str: Output from the remote command execution
    &amp;#34;&amp;#34;&amp;#34;
    # Escape special characters in password and command to prevent shell injection
    escaped_password = password.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    escaped_command = command.replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;\\&amp;#39;&amp;#39;&amp;#34;)
    
    ssh_command = (
        f&amp;#34;sshpass -p &amp;#39;{escaped_password}&amp;#39; &amp;#34;
        f&amp;#34;ssh -o StrictHostKeyChecking=no &amp;#34;
        f&amp;#34;{username}@{host} -p {port} &amp;#34;
        f&amp;#34;&amp;#39;{escaped_command}&amp;#39;&amp;#34;
    )
    return run_command(ssh_command)
 
```&lt;/p&gt;
&lt;p&gt;Note how only *password* and *command* inputs are escaped to prevent shell injection; while *username*, *host* and *port* values are left injectable.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Create an `index.html` file wit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-302</guid>
    </item>
  </channel>
</rss>
