PT-2026-38591 · Miniclaw · Miniclaw

·

CVE-2026-8112

·

Published

2026-05-07

·

Updated

2026-05-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 8421bit MiniClaw versions up to 223c16a1088e138838dcbd18cd65a37c35ac5a84
Description Remote OS command injection can occur via the executeCognitivePulse() function located in the src/kernel.ts file. This allows a remote attacker to execute arbitrary operating system commands through manipulation of the function.
Recommendations Deploy patch 028f62216dee9f64833d0f1cfda7c217067ceba8 for versions up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. As a temporary workaround, restrict access to the executeCognitivePulse() function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8112

Affected Products

Miniclaw