PT-2025-50557 · Unknown · Cybersecurity Ai

Published

2025-12-10

·

Updated

2025-12-12

·

CVE-2025-67511

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cybersecurity AI (CAI) versions 0.5.9 and below
Description Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. The run ssh command with credentials() function, accessible to AI agents, is susceptible to Command Injection. While the password and command inputs are escaped to prevent shell injection, the username, host, and port values are injectable. This flaw allows attackers to manipulate backend routing logic by crafting malicious parameters, potentially gaining control over the system without authentication.
Recommendations Versions 0.5.9 and below: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-67511
GHSA-4C65-9GQF-4W8H

Affected Products

Cybersecurity Ai