PT-2026-38591 · Miniclaw · Miniclaw
Ybdesire
·
Published
2026-05-07
·
Updated
2026-05-10
·
CVE-2026-8112
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
8421bit MiniClaw versions up to 223c16a1088e138838dcbd18cd65a37c35ac5a84
Description
Remote OS command injection can occur via the
executeCognitivePulse() function located in the src/kernel.ts file. This allows a remote attacker to execute arbitrary operating system commands through manipulation of the function.Recommendations
Deploy patch 028f62216dee9f64833d0f1cfda7c217067ceba8 for versions up to 223c16a1088e138838dcbd18cd65a37c35ac5a84.
As a temporary workaround, restrict access to the
executeCognitivePulse() function to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Miniclaw